Security

Unknown splunk cloud role

randy_moore
Path Finder

When I run a report of roles that have been modified in our splunk cloud instance I see these entries

Date         Time     user       action    info     role_name
04-06-20    16:50:18    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:50:15    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:49:52    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:44:06    _ops_admin  edit_user   granted _ops_admin
04-06-20    16:44:03    _ops_admin  edit_user   granted _ops_admin

We dont have that user or role name defined in our instance. Anyone have an idea of what this is and if I should be concerned?

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Values beginning with "_" are often reserved by Splunk. Perhaps this is a user/role Splunk uses to manage your Cloud instances.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...