<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Modify Splunk user role via the REST API in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360295#M65733</link>
    <description>&lt;P&gt;If this is related to &lt;A href="https://answers.splunk.com/answers/561656/adding-users-via-rest-api-on-search-head-cluster.html"&gt;https://answers.splunk.com/answers/561656/adding-users-via-rest-api-on-search-head-cluster.html&lt;/A&gt; then don't touch config files on the search heads. SHC doesn't like that.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2017 14:05:17 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2017-08-09T14:05:17Z</dc:date>
    <item>
      <title>Modify Splunk user role via the REST API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360292#M65730</link>
      <description>&lt;P&gt;I have about 125 accounts I need to change the role on. This has to be possible via the REST API. Any thoughts from anyone out there in splunk land?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 12:45:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360292#M65730</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2017-08-09T12:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Modify Splunk user role via the REST API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360293#M65731</link>
      <description>&lt;P&gt;Ideally, you'd move the users into different groups in your LDAP, or map the users' group to a different role in your LDAP mapping inside of splunk.&lt;/P&gt;

&lt;P&gt;Failing that, you can of course modify users via REST - after all, any click you do in the UI translates to a REST call under the hood. Check out &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/RESTREF/RESTaccess#authentication.2Fusers"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/RESTREF/RESTaccess#authentication.2Fusers&lt;/A&gt; - the POST takes a roles parameter to update role assignment.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 13:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360293#M65731</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2017-08-09T13:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Modify Splunk user role via the REST API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360294#M65732</link>
      <description>&lt;P&gt;I'd edit the configuration file from the CLI.  By the time you scripted a solution via the REST API, you could have hand-typed the changes (of course you should be using search-and-replace tools, not hand editing everything)&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 13:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360294#M65732</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-09T13:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Modify Splunk user role via the REST API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360295#M65733</link>
      <description>&lt;P&gt;If this is related to &lt;A href="https://answers.splunk.com/answers/561656/adding-users-via-rest-api-on-search-head-cluster.html"&gt;https://answers.splunk.com/answers/561656/adding-users-via-rest-api-on-search-head-cluster.html&lt;/A&gt; then don't touch config files on the search heads. SHC doesn't like that.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 14:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360295#M65733</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2017-08-09T14:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Modify Splunk user role via the REST API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360296#M65734</link>
      <description>&lt;P&gt;It does if you do it on the Deployer &lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 15:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Modify-Splunk-user-role-via-the-REST-API/m-p/360296#M65734</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-09T15:31:09Z</dc:date>
    </item>
  </channel>
</rss>

