The search query it showing only the roles for currently logged-in user. But this is not what we are looking for, we need list of users with logmon_app* roles.
| rest /services/authorization/roles/ | search title="logmon_app*" | table title | rename title as roles | join type=left role max=0 [| rest /services/authentication/users | table roles title | rename title as userName | mvexpand roles | search roles="logmon_app*" ] | stats values(userName) as username by roles |eval rolepresent="yes"
You could try with
| rest /servicesNS/-/-/authorization/roles/
| rest /servicesNS/-/-/authentication/users
although I can't guarantee it will work
Hi
this could be a little bit tricky when user/role have some inherited roles which could also contains some other inherited roles etc...
One way to solve this is use e.g. this app https://splunkbase.splunk.com/app/4111 and then modify those queries to solve your issues, if that didn't already solved it.
r. Ismo