Splunk Search

Query to find out users belong to a particular role

Path Finder

Is there any query to find out users belong to a particular role . For example , if i have a role called "least_role" , how can i checkout how many users in splunk are having this role and their names .

0 Karma
1 Solution

Splunk Employee
Splunk Employee

Try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| search roles=admin

Change the value of roles in the last bit to the role you want to search on.

If you want a table of all roles and users assigned to each role, try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| sort roles

View solution in original post

Splunk Employee
Splunk Employee

Try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| search roles=admin

Change the value of roles in the last bit to the role you want to search on.

If you want a table of all roles and users assigned to each role, try this:

| rest /services/authentication/users splunk_server=local 
| fields roles title realname 
| rename title as username 
| sort roles

View solution in original post

SplunkTrust
SplunkTrust

It would be worth mentioning that the query shows you users with that role who have logged in, not users who are in an LDAP system with that role or similar.

I'm also assuming the userlist in Splunk from recent logins is limited in some ways...

0 Karma