Splunk Enterprise

Unable to get complete users list from | rest /services/authentication/users

bishtk
Communicator

Hi All,

We  are having multisite splunk architecture (version 8.1.0) and using LDAP for users authentication.

We are not getting complete list of users using | rest /services/authentication/users.

Although I checked on each SH member and able to see all users inside /opt/splunk/etc/users/

I already checked few technotes:

https://community.splunk.com/t5/Security/Users-missing-from-Access-Control/m-p/487058

Wrt above technote, we don't have those two attributes (edit_roles_grantable, grantableRoles) enabled already, so the above technote is of no use for my issue.

Also I did rolling restart but still users are not reflecting in rest search query.

Please suggest?

Thanks,

0 Karma

gjanders
SplunkTrust
SplunkTrust

There are multiple potential issues here, how many of the users are you seeing/missing?

With that tech note I recently experienced the issue and created a search to detect in Alerts for Splunk Admins 

Or github link there is an alert : "SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI"

So that can find if you did hit that particular issue.

Other potential issues might be the query limit of the LDAP, you can enable paged queries from Splunk *or* it could be the ldap users to precache limit...

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you try this?

| rest /servicesNS/-/-/authentication/users

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

bishtk
Communicator

Hi @richgalloway 

Thanks but both rest queries are meant to perform same operations.

And so even with this query I am getting same results

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...