All Apps and Add-ons

SA-ldapsearch lastLogon attr not returns value

louismai
Path Finder

Hi,

I ran a query:
| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs="sAMAccountName,distinguishedName,lastLogon,lastLogonTimestamp,division"

I found there are couple accounts witch lastLogon is null. But that field has value when I check that account in Active Directory. It is confusing because only some accounts have that issue.

Tks
Linh

0 Karma

spayneort
Contributor

The lastLogon attribute is not replicated between domain controllers. You may be getting a null value if the user has not logged on using the domain controller that ldapsearch is connecting to.

0 Karma

louismai
Path Finder

When I run a script in PowerShell on the same user, the PowerShell script returns a non-null value, while the app Active Directory still receives null value. It is very strange.

Tks
Louis

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...