Reporting

List of all Admin Users report

dcrooks_cbp
New Member

I have the search to list the Admins in Splunk. I need to have it as a saved search or dashboard a non-Admin can save the screen shot. Seems I need like to run the search in elevated privileges. Any ideas?

Tags (1)
0 Karma

somesoni2
Revered Legend

You, as a admin, can setup a summary index OR a lookup table with list of Admin users. That way you can make it available to non-admin users (by setting proper permissions for the index or for the lookup table). You can use 2nd link from @harishalipaka's comment below for query to get the list.

0 Karma

dcrooks_cbp
New Member

Yes, I have the search. Just wish Splunk had a way a user could run the search as an admin to get all the results. I think we also tried to do a scheduled report and that failed.

0 Karma

somesoni2
Revered Legend

I would suggest you save your scheduled search report into a lookup table (using outputlookup command) OR into a summary index (to an index accessible by all). Then your non-admin users can write a search based off your lookup table (inputlookup command) OR against the summary index.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...