We are using Splunk Authorization and I found 67 unexpected users in "Manager » Access controls » Users" list. Not only that; but they are all marked "Authentication system = Scripted".
I would like to know who created these users and when. I have tried with:
index=_audit action="edit_user" operation="create" (searching "All time").
But that only gives me the "normal" users - and not even all of them.
How can I see who created the rest of the users?