Is there any query to find out users belong to a particular role . For example , if i have a role called "least_role" , how can i checkout how many users in splunk are having this role and their names .
Try this:
| rest /services/authentication/users splunk_server=local
| fields roles title realname
| rename title as username
| search roles=admin
Change the value of roles in the last bit to the role you want to search on.
If you want a table of all roles and users assigned to each role, try this:
| rest /services/authentication/users splunk_server=local
| fields roles title realname
| rename title as username
| sort roles
Try this:
| rest /services/authentication/users splunk_server=local
| fields roles title realname
| rename title as username
| search roles=admin
Change the value of roles in the last bit to the role you want to search on.
If you want a table of all roles and users assigned to each role, try this:
| rest /services/authentication/users splunk_server=local
| fields roles title realname
| rename title as username
| sort roles
It would be worth mentioning that the query shows you users with that role who have logged in, not users who are in an LDAP system with that role or similar.
I'm also assuming the userlist in Splunk from recent logins is limited in some ways...
When using ldap this shows cached users which has a limit...you can increase the limit in splunk config if you have a large user base.
Furthermore enable paging is required if you cannot obtain all users from a single query, available in 7.3 and above
With the right settings I can see over 3000 users after restart