Security

Current logged in user in 6.3

grossb
Explorer

Hello,
The current recommendations to use "| rest /services/authentication/current-context" to find the current logged in user do not work in 6.3.1. What is the alternative?

Thanks,
Brett

0 Karma
1 Solution

javiergn
Super Champion

Try specifying the local server:

| rest /services/authentication/current-contex splunk_server=local

View solution in original post

javiergn
Super Champion

Try specifying the local server:

| rest /services/authentication/current-contex splunk_server=local

grossb
Explorer

This worked for me after fixing the typo. Thank you very much!

"| rest /services/authentication/current-context splunk_server=local"

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

Hi Brett

What specifically isn't working for you? The command works as expected for me.

0 Karma

grossb
Explorer

I kept getting "Splunk-System-User" as the username when using the command above. Adding "splunk_server=local" as noted in the answer brought the correct current logged in user.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...