We would like to produce a report which lists all the users who belong to a certain ldap group.
The following brings users -
| rest services/authentication/users | where roles="xxx" | table title, email, realname
We are not sure whether this call brings back what we want or rather all users of this ldap group who are currently logged in.
The REST point you're calling represents all users and not just currently logged in users. Therefore what is returned should be representative of all users mapped into the given role whether they are system or LDAP user.
Always good to keep the REST URI Quick Reference link in your back pocket: http://docs.splunk.com/Documentation/Splunk/6.4.0/RESTREF/RESTlist
View solution in original post
Perfect joshd. This is what I thought. Much appreciated.