Splunk Enterprise

Unable to get complete users list from | rest /services/authentication/users

bishtk
Communicator

Hi All,

We  are having multisite splunk architecture (version 8.1.0) and using LDAP for users authentication.

We are not getting complete list of users using | rest /services/authentication/users.

Although I checked on each SH member and able to see all users inside /opt/splunk/etc/users/

I already checked few technotes:

https://community.splunk.com/t5/Security/Users-missing-from-Access-Control/m-p/487058

Wrt above technote, we don't have those two attributes (edit_roles_grantable, grantableRoles) enabled already, so the above technote is of no use for my issue.

Also I did rolling restart but still users are not reflecting in rest search query.

Please suggest?

Thanks,

0 Karma

gjanders
SplunkTrust
SplunkTrust

There are multiple potential issues here, how many of the users are you seeing/missing?

With that tech note I recently experienced the issue and created a search to detect in Alerts for Splunk Admins 

Or github link there is an alert : "SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI"

So that can find if you did hit that particular issue.

Other potential issues might be the query limit of the LDAP, you can enable paged queries from Splunk *or* it could be the ldap users to precache limit...

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you try this?

| rest /servicesNS/-/-/authentication/users

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

bishtk
Communicator

Hi @richgalloway 

Thanks but both rest queries are meant to perform same operations.

And so even with this query I am getting same results

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...