Issue is using 'admon' input on Windows with Splunk 6.x some of the key column for AD Schema are wrong, this seems like a regression as it worked on Splunk Version 5.x.
The attributes like pwdLastSet,badPasswordTime,lastLogon,lastLogonTimestamp,whenChanged – all have the same exact time stamp
This behavior has been confirmed as Bug between Splunk Version 6.x and current release 6.0.3. It is expected to be fixed in Splunk Release 6.0.5. Bug Number
SPL-83047:ADmon: Timestamp fields (pwdLastSet, badPasswordTime, lastlogonTimestamp, etc.) are not being retrieved accurately from the AD record
This behavior has been confirmed as Bug between Splunk Version 6.x and current release 6.0.3. It is expected to be fixed in Splunk Release 6.0.5. Bug Number
SPL-83047:ADmon: Timestamp fields (pwdLastSet, badPasswordTime, lastlogonTimestamp, etc.) are not being retrieved accurately from the AD record
I'm still seeing this behavior in Splunk 6.0.6 build 228831 and Splunk_for_ActiveDirectory 1.2.2
any idea of the ETA of fixing this? does this affect ldapsearch or enterprise security?