Change Auditor will not show the correct LDAP Search Filter for AD Queries when a more complex filter has been used.
In the below example DSQUERY is used with a filter for the objectClass, objectCategory, and memberOf attributes.
dsquery * -filter "(&(objectclass=user)(objectCategory=CN=Person,CN=Schema,CN=Configuration,DC=rootdom,DC=local)(memberOf=CN=My Admins,DC=rootdom,DC=local))" -attr objectguid -server controller2 -gc
Once the command was executed you should see an AD Query event inside Change Auditor.
The expected result would be the entire above filter is displayed inside the AD Query event which is collected by Change Auditor.
Instead the filter appears as "objectclass=?" with a question mark and it is incomplete.