Security

Help in identifying the capabilities for REST search to fetch User/Role/App details

harshal_chakran
Builder

Hi all,
I have the below rest searches to fetch the User, Role and Application details, respectively.

  • | rest /services/authentication/users
  • | rest /services/authorization/roles
  • | rest /services/apps/local

However, am not able to define the exact read only capabilities for my role to assign, so I can run these searches to get the results.

Below are the capabilities I investigated:
edit_roles
edit_user
rest_properties_get
search

However, am not getting the entire application list as compared to Admin role. Also the edit_roles and edit_user are giving write permission and am looking for read permission only.

Please help.

0 Karma

koshyk
Super Champion

Please check if the answer https://answers.splunk.com/answers/745460/rest-call-in-subsearch.html helps you
The original query is for indexes, but you can put the other REST endpoints change to see if it works.

0 Karma

adonio
Ultra Champion

Can you elaborate a little here?
what is the problem you are trying to solve?
What is the outcome / search output you are anticipating?

0 Karma

harshal_chakran
Builder

I have a certain dashboard listing all Splunk users and what role-capabilities are assigned to them. For which I have used the above mentioned Rest API commands.

However the dashboard users are not able to see the results as they don't below capabilities.

edit_roles
edit_user
rest_properties_get
search

If I assign these capabilities to them, then they can delete/update the user-role information from GUI settings, which I don't want.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...