<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Which users use the REST API? in Security</title>
    <link>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509714#M11619</link>
    <description>&lt;P&gt;We are planning to move to SAML SSO soon. One of the drawbacks of SAML is that you cannot authenticate on the API any longer. Up to this point, any user defined to use splunkweb has had access to the API. How can I find out who will be impacted by yanking API access?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2020 13:57:17 GMT</pubDate>
    <dc:creator>twinspop</dc:creator>
    <dc:date>2020-07-17T13:57:17Z</dc:date>
    <item>
      <title>Which users use the REST API?</title>
      <link>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509714#M11619</link>
      <description>&lt;P&gt;We are planning to move to SAML SSO soon. One of the drawbacks of SAML is that you cannot authenticate on the API any longer. Up to this point, any user defined to use splunkweb has had access to the API. How can I find out who will be impacted by yanking API access?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 13:57:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509714#M11619</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2020-07-17T13:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Which users use the REST API?</title>
      <link>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509735#M11620</link>
      <description>&lt;P&gt;I'd start with this query.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal source="*splunkd_access.log" NOT (user="-" OR user="splunk-system-user")
| dedup user
| table user&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 17 Jul 2020 15:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509735#M11620</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-17T15:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Which users use the REST API?</title>
      <link>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509740#M11621</link>
      <description>&lt;P&gt;The catches both API and splunkweb users. I'm not clear how to isolate them&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 15:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/509740#M11621</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2020-07-17T15:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Which users use the REST API?</title>
      <link>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/510158#M11628</link>
      <description>&lt;P&gt;Try:&lt;/P&gt;&lt;P&gt;SearchHeadLevel - platform_stats.audit metrics users&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/gjanders/SplunkAdmins/blob/master/default/savedsearches.conf" target="_self"&gt;SplunkAdmins GitHub &lt;/A&gt;&amp;nbsp;or &lt;A href="https://splunkbase.splunk.com/app/3796/" target="_self"&gt;Alerts for Splunk Admins (splunkbase)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 04:39:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Which-users-use-the-REST-API/m-p/510158#M11628</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-07-21T04:39:43Z</dc:date>
    </item>
  </channel>
</rss>

