Splunk Enterprise Security

List of users on Linux and Windows clients, how we can get it?

infosec_kicb
New Member

Hi guys,
Nothing comes to mind. How to get a list of users in operating systems using splunk forwarder?

0 Karma

saramamurthy_sp
Splunk Employee
Splunk Employee

Are you speaking about Linux or Splunk Users?

if Linux Users, you have to install on your forwarder a TA-Linux that contains a script to collect Linux users.

If you don't want to install the full TA_Linux, you can take only the script to extract users ($SPLUNK_HOME/etc/apps/Splunk_TA_nix/ bin/usersWithLoginPrivs.sh).

After you can search them in Splunk with a simple search ( index=os | dedup users | table users ).

Cheers.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...