Security

Unknown splunk cloud role

randy_moore
Path Finder

When I run a report of roles that have been modified in our splunk cloud instance I see these entries

Date         Time     user       action    info     role_name
04-06-20    16:50:18    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:50:15    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:49:52    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:44:06    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:44:03    _ops_admin  edit_user   granted _ops_admin

We dont have that user or role name defined in our instance. Anyone have an idea of what this is and if I should be concerned?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Values beginning with "_" are often reserved by Splunk. Perhaps this is a user/role Splunk uses to manage your Cloud instances.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...