Splunk Search

Query to find out users belong to a particular role

kteng2024
Path Finder

Is there any query to find out users belong to a particular role . For example , if i have a role called "least_role" , how can i checkout how many users in splunk are having this role and their names .

0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

Try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| search roles=admin

Change the value of roles in the last bit to the role you want to search on.

If you want a table of all roles and users assigned to each role, try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| sort roles

View solution in original post

kmorris_splunk
Splunk Employee
Splunk Employee

Try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| search roles=admin

Change the value of roles in the last bit to the role you want to search on.

If you want a table of all roles and users assigned to each role, try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| sort roles

gjanders
SplunkTrust
SplunkTrust

It would be worth mentioning that the query shows you users with that role who have logged in, not users who are in an LDAP system with that role or similar.

I'm also assuming the userlist in Splunk from recent logins is limited in some ways...

gjanders
SplunkTrust
SplunkTrust

When using ldap this shows cached users which has a limit...you can increase the limit in splunk config if you have a large user base.

Furthermore enable paging is required if you cannot obtain all users from a single query, available in 7.3 and above 

 

With the right settings I can see over 3000 users after restart 

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...