Security

disabled user list

Mohsin123
Path Finder

how to get list of disabled users in splunk ? any query ?

i was checking for orphaned object query :

| rest timeout=600 splunk_server=local /servicesNS/-/-/saved/searches add_orphan_field=yes count=0
| search orphan=1

does it help ?

0 Karma

mayurr98
Super Champion

do you mean inactive users?

 | rest /services/authentication/users splunk_server=local 
 | fields realname, title
 | rename title as user
 | join user type=left [
    | search index=_audit action="login attempt" earliest=-12mon
    | stats max(timestamp) as _time by user, sourcetype
 ]
 | where isnull(sourcetype)
 | fields - sourcetype

Also, have a look at this answer
https://answers.splunk.com/answers/481/search-for-inactive-splunk-users.html

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...