We are having multisite splunk architecture (version 8.1.0) and using LDAP for users authentication.
We are not getting complete list of users using | rest /services/authentication/users.
Although I checked on each SH member and able to see all users inside /opt/splunk/etc/users/
I already checked few technotes:
Wrt above technote, we don't have those two attributes (edit_roles_grantable, grantableRoles) enabled already, so the above technote is of no use for my issue.
Also I did rolling restart but still users are not reflecting in rest search query.
There are multiple potential issues here, how many of the users are you seeing/missing?
With that tech note I recently experienced the issue and created a search to detect in Alerts for Splunk Admins
Or github link there is an alert : "SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI"
So that can find if you did hit that particular issue.
Other potential issues might be the query limit of the LDAP, you can enable paged queries from Splunk *or* it could be the ldap users to precache limit...
Did you try this?
| rest /servicesNS/-/-/authentication/users
Thanks but both rest queries are meant to perform same operations.
And so even with this query I am getting same results