Windows DCs return the NETLOGON_NTLMV2_ENABLED flag in the netr_LogonSamLogon* response, while samba does not. This doesn't have any real effect. But it seems that NTLMSSP NTLMv2 authentications against a Windows member server in a samba domain, result in event log messages with "lmPackageName": "NTLM V1", instead of "NTLM V2".
This bug was referenced in samba master: 9bab6426b9fc4d2464597fdfa3085ea259b77710 1414004ee953975c50e0ee374684ff8e01246946 10f38aff7c23dc20bc98cf0e02a430f8b0d7b1ad
Created attachment 18534 [details] 4.21 backport backport fix for 4.21 ...
Created attachment 18538 [details] Patches for v4-21-test
Created attachment 18539 [details] Patches for v4-20-test
Pushed to autobuild-v4-{21,20}-test.
This bug was referenced in samba v4-20-test: d5a2358e3eb05af9c206ce61edeaf344ca02c511 3dda8cc57f7b75c811b24257829f3e54a242c1c6
This bug was referenced in samba v4-21-test: 3bbcf93686c0bdba2c1685cffc7b01d1f906f7da bbbaf264d1b4501ab8bb839352d90b492d3c62fb
Closing out bug report. Thanks!