Hello,
I have this ldapsearch that returns 10's of thousands of records.
| ldapsearch search=(&(objectClass=User)(!(objectClass=computer)))
I want to filter on the whenCreated attribute to return new users in the past 7 days, sliding window. Is it possible to perform filtering by one or more attributes on the ldapsearch command line? I know I can use Splunk evals after the ldapsearch command to do this.
Thanks and God bless,
Genesius
According to the docs at https://docs.splunk.com/Documentation/SA-LdapSearch/3.0.3/User/Theldapsearchcommand, the argument to the search option can be any RFC 2554-compliant string, which should include whenCreated.