Getting Data In

Why doesn't the LastLogon timestamp match betweeen the active directory (AD) and SA-LdapSearch information?

evinasco
Communicator

Good Morning,

I have been using SA-LdapSearch for a project. I have had the same issue with the time for I see results back, but I have other problems. I need the user's "last logon" information. When I compare with AD directly, information does not match with the SA-LdapSearch information. At AD the "last logon" is topday, at SA-LdapSearch the "last logon" was yesterday.

Has this happened to anybody else?

Regards

0 Karma

the0duke0
Path Finder

The LastLogon time stamp can vary from Domain Controller to Domain Controller as LastLogon is not replicated. lastLogonTimeStamp is replicated, but it is on a delay so this value will be 10-14 days behind. The main use for this field is to find accounts that are stale (i.e. >90 days old). https://blogs.technet.microsoft.com/askds/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-de...

richgalloway
SplunkTrust
SplunkTrust

I converted this to a question from a comment on an unrelated subject.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...