Splunk Search

Query to find out users belong to a particular role

kteng2024
Path Finder

Is there any query to find out users belong to a particular role . For example , if i have a role called "least_role" , how can i checkout how many users in splunk are having this role and their names .

0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

Try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| search roles=admin

Change the value of roles in the last bit to the role you want to search on.

If you want a table of all roles and users assigned to each role, try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| sort roles

View solution in original post

kmorris_splunk
Splunk Employee
Splunk Employee

Try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| search roles=admin

Change the value of roles in the last bit to the role you want to search on.

If you want a table of all roles and users assigned to each role, try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| sort roles

gjanders
SplunkTrust
SplunkTrust

It would be worth mentioning that the query shows you users with that role who have logged in, not users who are in an LDAP system with that role or similar.

I'm also assuming the userlist in Splunk from recent logins is limited in some ways...

gjanders
SplunkTrust
SplunkTrust

When using ldap this shows cached users which has a limit...you can increase the limit in splunk config if you have a large user base.

Furthermore enable paging is required if you cannot obtain all users from a single query, available in 7.3 and above 

 

With the right settings I can see over 3000 users after restart 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...