Hi!
I found this accesslog entry, caused by a server-sync it seems (some strings replaced consistently for privacy):
---
dn: reqStart=20200722085045.000019Z,cn=audit
objectClass: auditModify
structuralObjectClass: auditModify
reqStart: 20200722085045.000019Z
reqEnd: 20200722085045.000060Z
reqType: modify
reqSession: 6
reqAuthzID: cn=Admin,dc=example,dc=org
reqDN: uid=username,ou=people,dc=example,dc=org
reqResult: 0
reqMod: entryCSN:= 20200722082119.640611Z#000000#003#000000
reqMod: modifiersName:= cn=Admin,dc=example,dc=org
reqMod: modifyTimestamp:= 20200722082119Z
reqOld: entryCSN: 20200722082119.640611Z#000000#003#000000
reqOld: modifiersName: cn=Admin,dc=example,dc=org
reqOld: modifyTimestamp: 20200722082119Z
reqEntryUUID: 2d063f78-7ced-1032-948d-cf46530da60d
entryUUID: 2cefa3e8-6044-103a-8b01-193e5edbb211
creatorsName: cn=audit
createTimestamp: 20200722082119Z
entryCSN: 20200722082119.640611Z#000000#003#000000
modifiersName: cn=audit
modifyTimestamp: 20200722082119Z
---
So if I see it correctly, only the entryUUID changed? Actually I wouldn't expect the entryUUID to change. Obviously the entry could not have been recreated after being deleted, because otherwise some other field would have changed, right? Or could this be a late consequence of improper slapadd (entryUUIDs not taken from slapcat) long time ago?
Regards,
Ulrich