Splunk Enterprise

Unable to get complete users list from | rest /services/authentication/users

Path Finder

Hi All,

We  are having multisite splunk architecture (version 8.1.0) and using LDAP for users authentication.

We are not getting complete list of users using | rest /services/authentication/users.

Although I checked on each SH member and able to see all users inside /opt/splunk/etc/users/

I already checked few technotes:


Wrt above technote, we don't have those two attributes (edit_roles_grantable, grantableRoles) enabled already, so the above technote is of no use for my issue.

Also I did rolling restart but still users are not reflecting in rest search query.

Please suggest?


0 Karma


There are multiple potential issues here, how many of the users are you seeing/missing?

With that tech note I recently experienced the issue and created a search to detect in Alerts for Splunk Admins 

Or github link there is an alert : "SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI"

So that can find if you did hit that particular issue.

Other potential issues might be the query limit of the LDAP, you can enable paged queries from Splunk *or* it could be the ldap users to precache limit...

Alerts for Splunk Admins https://splunkbase.splunk.com/app/3796/
Version Control for Splunk https://splunkbase.splunk.com/app/4355/
0 Karma


Did you try this?

| rest /servicesNS/-/-/authentication/users


If this reply helps you, an upvote would be appreciated.
0 Karma

Path Finder

Hi @richgalloway 

Thanks but both rest queries are meant to perform same operations.

And so even with this query I am getting same results

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.