All Apps and Add-ons

ldapsearch not getting all key/properties/fields from AD


In our environment when we run the powershell command to get a user's properties on AD server by running the below command we get 168 keys/properties/fields

Get-ADUser <username> -Properties *

However when I use ldapsearch command from Splunk for the same user I only get 83 properties.
| ldapsearch domain=mydomain search="(&(objectClass=user)(sAMAccountName=username))"

Some of the properties which are missing and we are interested are accountExpires, badPwdCount, scriptPath which are mentioned in the below question.

I am seeing the above scenario on both (1.1.13 and 2.1.1) release of SA-ldapsearch. Am I missing some configuration which will fetch the missing properties?

0 Karma

Path Finder

Hi Kozanic,

Not sure why it only returns some results if doing just a basic search but if the attribute is in the LDAP schema then ldapsearch will pick it up, you just need to place the extra fields into a table output


| table sAMAccountName, personalTitle, displayName, ..., pwdLastSet, badPasswordTime, badPwdCount, logonCount, etc....
0 Karma

Path Finder


I actually found that the port you use to query on also affects the number of attributes returned.

I think the default returns less - but is slightly faster. I have updated to use port 389 which seems to return a lot more - but does take a little longer.

Path Finder

Hi bohrasaurabh,

Just wondering if you ever figured this one out?

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...