Security

Search for Splunk logon and role info

maciep
Champion

Is there anyway to list users who have logged into Splunk along with the Splunk roles they are mapped to? I can get the first part with the search below, but I don't know how to tie their roles to the results.

index=_audit action="login attempt" | dedup user | sort user | table user

Tags (1)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Try this ... index=_audit action="login attempt" | dedup user | join [| rest /services/authentication/users ] | table user roles

View solution in original post

rroberts
Splunk Employee
Splunk Employee

Try this ... index=_audit action="login attempt" | dedup user | join [| rest /services/authentication/users ] | table user roles

maciep
Champion

It didn't work for me either but got me down the right path. Unless I was doing something wrong, I had to rename user to title to join it to the rest data. I also added the timestamp and limited it to the role I'm interested in. The results look accurate. Using Splunk 6 by the way (didn't mention it earlier)

index=_audit action="login attempt" | eval last=max(timestamp) | dedup user | rename user as title | join title [| rest /services/authentication/users] | search roles=cerner | table title roles last | sort title

Thanks for your help!!

0 Karma

rroberts
Splunk Employee
Splunk Employee

Glad you found it useful!

0 Karma

zenmoto
Path Finder

This is super clever, but it doesn't work for me- I correctly get a list of logged-in users, but with the roles all incorrectly as 'user'. I modified your search slightly and it seems to work for me-

index=_audit action="login attempt" | dedup user | join user [| rest /services/authentication/users | rename title as user ] | table user, roles

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...