Integrations
- Integrations
- 1Password
- Abnormal
- Absolute
- AbuseIPDB
- Acronis
- Adaptive Shield
- Adobe Cloud
- ADP
- Agari Phishing Response
- Airlock
- Airlock Digital
- Akamai Identity Cloud Social
- Alert Logic
- AlgoSec Firewall Analyzer
- Alienvault OTX
- Alienvault USM
- Anthropic
- Anodot
- Any Run
- Ansible
- Anvilogic
- Apex One
- ArcSight ESM
- Area 1
- Asana
- Asset Panda
- Atlassian Crowd
- Atlassian User Management
- Atlassian User Provisioning
- AuditBoard
- auth0
- Authentik
- Authomize
- Automox
- AWS
- AWS IAM Identity Center
- Axonius
- Azure
- Azure Data Explorer
- Azure DevOps
- Azure Log Analytics
- Azure Storage
- BambooHR
- Big Fix
- BigPanda
- Bitbucket
- Bitdefender
- Bitsight
- Bitwarden
- Black Duck
- Black Kite
- Blink
- BMC Remedy
- Box
- Brinqa
- Cato Networks
- Censys
- Chorus
- Cisco Advanced Phishing Protection
- Cisco Domain Protection
- Cisco Meraki
- Cisco Talos
- Cisco Umbrella
- Cisco Webex
- Claroty xDome
- ClearPass
- ClickHouse
- ClickUp
- Cloud Custodian
- Cloudflare
- Cloudflare R2
- Cobalt.io
- Check Point Harmony
- Check Point Infinity Events
- Check Point Management
- Check Point XDR/XPR
- Checkmarx SAST
- Checkmarx One
- Chronicle
- Compass
- Confluence
- Confluence Data Center
- Coralogix
- Coralogix Incident Management
- Cortex XDR
- Cortex Xpanse
- CredStash
- Cribl
- CrowdStrike
- CyberArk
- Cybersixgill
- CyCognito
- Cyera
- Cylance
- Cyware CTIX
- Darktrace
- Dasera
- Databricks
- Datadog
- DataSet
- Discord
- Docusign
- Delighted
- Delinea
- Devo
- Domo
- Drata
- Dropbox
- Dropbox Business
- druva
- Duo
- Duo Auth
- Dynatrace
- EasyVista
- EchoTrail
- Egnyte
- Egnyte Secure Govern
- Elasticsearch
- Entro
- Ermetic
- Exabeam
- Exchange Online
- Expel
- F5
- Falcon LogScale
- Falcon Surface
- Flare.io
- Forcepoint DLP
- Forescout
- FortiGate
- Freshservice
- GCP
- Gemini
- Ghostwriter
- Git
- GitHub
- GitLab
- Glean
- Gmail
- Google Calendar
- Google Chat
- Google Docs
- Google Drive
- Google Forms
- Google Meet
- Google Looker
- Google Sheets
- Google Workspace
- Grafana
- Greenhouse
- GreyNoise
- Grip Security
- GYTPOL
- Have I Been Pwned
- HackerOne
- Halo Service Desk
- HiBob
- HubSpot
- Hunters
- Hybrid Analysis
- Hyperproof
- IBM CLoud
- IBM NS1 Connect
- IBM X Force
- Imperva
- Incident.io
- Infobip
- Infoblox Cloud Services Portal
- Intercom
- Intezer
- IP API
- IPinfo
- IPWHOIS
- Ivanti RiskSense
- Ironscales
- Jamf
- JetBrains
- JFrog
- Jira
- Jira Data Center
- Joe Sandbox
- JumpCloud
- Kandji
- Keeper Secrets Manager
- Kenna Security
- KnowBe4
- KnowBe4 Events
- Kubernetes
- Lacework
- LaunchDarkly
- Linear
- Litmos
- LogicMonitor
- LogRhythm
- Manage Engine ServiceDesk Plus
- Mattermost
- Maven
- Microsoft Defender For Cloud
- Microsoft Defender For Cloud Apps
- Microsoft Defender For Endpoints
- Microsoft Defender XDR
- Microsoft E-Discovery
- Microsoft Entra ID
- Microsoft Graph
- Microsoft Intune
- Microsoft Office 365 Management Activity
- Microsoft Outlook
- Microsoft Purview
- Microsoft Sentinel
- Microsoft SQL Server
- Microsoft Teams
- Mimecast
- MISP
- Monday
- MongoDB Atlas
- MxToolbox
- Neo4j
- NetBox
- Netography
- Netskope
- New Relic
- Nightfall AI
- NinjaOne
- Notion
- Nozomi Networks
- Nuclei
- Nucleus
- Nutanix Hypervisor
- Obsidian
- Okta
- OneDrive
- OneLogin
- OneTrust
- Oort
- OpenAI
- OpenCTI
- Opsgenie
- OPSWAT
- Oracle Cloud
- Oracle HCM
- Orca Security
- OWASP ZAP
- PagerDuty
- Palo Alto NGFW
- Palo Alto Firewall
- Panther
- Pentera
- Perception Point
- PhishLabs
- PhishLabs Incident Data
- PhishLabs Open Web Monitoring
- Pingdom
- PingID
- PingOne
- PlexTrac
- PortSwigger
- Power BI
- PowerShell
- Postman
- Postman SCIM
- Prisma Access
- Prisma Cloud
- Prisma Cloud CWP
- Prometheus
- Proofpoint
- Proofpoint ITM
- Proofpoint Protection Server
- Proofpoint Security Awareness Training
- Proofpoint TAP
- Proofpoint TRAP
- Pub-Sub
- QRadar
- Qualys
- Rapid7
- Rapid7 InsightIDR
- Rapid7 InsightVM Cloud
- Rapid7 Threat Command
- Reco
- Recorded Future
- Recorded Future Triage Cloud
- Red Hat IDM
- Rippling
- runZero
- SafeBase
- Sage HR
- SailPoint
- SailPoint IdentityIQ
- Salesforce
- SAP Ariba
- ScienceLogic
- Securin
- Securin VI
- SecurityScorecard
- Securonix
- Sekoia.io
- SemGrep
- SentinelOne
- ServiceNow
- SharePoint
- Shodan
- Shopify
- Silverfort
- Slack
- Smartsheet
- Snipe IT
- Snowflake
- Snyk
- SolarWinds Service Desk
- SonarQube
- Sophos
- Split
- Splunk
- Splunk Observability
- Splunk SOAR
- Spur
- StrongDM
- Sumo Logic
- Symantec EDR
- Sysdig
- Tableau
- Tanium
- TeamCity
- TeamViewer
- Telegram
- Tenable
- Tenable Security Center
- Terraform
- Terraform Cloud
- Tessian
- TheHive
- Thinkst Canary
- ThreatQuotient
- Trellix Email Security
- Trello
- Trend Vision One
- Twilio
- UKG HR
- Uptycs
- URLScan
- Vault
- Veracode
- Verkada
- Vertica
- VMware vSphere
- VMware Carbon Black
- VirusTotal
- WeChat
- WhatsApp
- WhoIs
- WildFire
- Wiz
- Workday
- Workspace ONE UEM
- YesWeHack
- Zendesk
- Zero Networks
- Zoom
- Zscaler Internet Access
- Zscaler Private Access
Actions
List Users
List all current users.
Parameters
Parameter | Description |
---|---|
Count | The maximum number of results to return. If value is set to 0, then all available results are returned. |
Offset | The first result (inclusive) from which to begin returning data. This value is 0-indexed. Default value is 0. In 4.1+, negative offsets are allowed and are added to count to compute the absolute offset (for example, offset=-1 is the last available offset). Offsets in the results are always absolute and never negative. |
Example Output
{
"links": {
"create": "/services/authentication/users/_new"
},
"origin": "/services/authentication/users",
"updated": "2023-01-15T10:34:32+02:00",
"generator": {
"build": "dd0128b1f8cd",
"version": "9.0.3"
},
"entry": [
{
"name": "example",
"id": "/services/authentication/users/example",
"updated": "1970-01-01T02:00:00+02:00",
"links": {
"alternate": "/services/authentication/users/example",
"list": "/services/authentication/users/example",
"edit": "/services/authentication/users/example"
},
"author": "system",
"acl": {
"app": "",
"can_list": true,
"can_write": true,
"modifiable": false,
"owner": "system",
"perms": {
"read": [
"*"
],
"write": [
"*"
]
},
"removable": false,
"sharing": "system"
},
"content": {
"capabilities": [
"accelerate_datamodel",
"accelerate_search",
"admin_all_objects",
"apps_backup",
"apps_restore",
"change_authentication",
"change_own_password",
"delete_messages",
"dispatch_rest_to_indexers",
"edit_authentication_extensions",
"edit_bookmarks_mc",
"edit_cmd",
"edit_deployment_client",
"edit_deployment_server",
"edit_dist_peer",
"edit_encryption_key_provider",
"edit_field_filter",
"edit_forwarders",
"edit_global_banner",
"edit_health",
"edit_httpauths",
"edit_indexer_cluster",
"edit_indexerdiscovery",
"edit_ingest_rulesets",
"edit_input_defaults",
"edit_kvstore",
"edit_local_apps",
"edit_log_alert_event",
"edit_manager_xml",
"edit_metric_schema",
"edit_metrics_rollup",
"edit_modinput_logd",
"edit_monitor",
"edit_own_objects",
"edit_restmap",
"edit_roles",
"edit_scripted",
"edit_search_concurrency_all",
"edit_search_head_clustering",
"edit_search_schedule_priority",
"edit_search_schedule_window",
"edit_search_scheduler",
"edit_search_server",
"edit_server",
"edit_server_crl",
"edit_sourcetypes",
"edit_splunktcp",
"edit_splunktcp_ssl",
"edit_splunktcp_token",
"edit_statsd_transforms",
"edit_tcp",
"edit_tcp_stream",
"edit_telemetry_settings",
"edit_token_http",
"edit_tokens_all",
"edit_tokens_own",
"edit_tokens_settings",
"edit_udp",
"edit_upload_and_index",
"edit_user",
"edit_view_html",
"edit_web_features",
"edit_web_settings",
"edit_workload_policy",
"edit_workload_pools",
"edit_workload_rules",
"embed_report",
"export_results_is_visible",
"fsh_manage",
"fsh_search",
"get_diag",
"get_metadata",
"get_typeahead",
"indexes_edit",
"input_file",
"install_apps",
"license_edit",
"license_tab",
"license_view_warnings",
"list_accelerate_search",
"list_all_objects",
"list_cascading_plans",
"list_deployment_client",
"list_deployment_server",
"list_dist_peer",
"list_forwarders",
"list_health",
"list_httpauths",
"list_indexer_cluster",
"list_indexerdiscovery",
"list_ingest_rulesets",
"list_inputs",
"list_introspection",
"list_metrics_catalog",
"list_pipeline_sets",
"list_remote_input_queue",
"list_remote_output_queue",
"list_search_head_clustering",
"list_search_scheduler",
"list_settings",
"list_storage_passwords",
"list_token_http",
"list_tokens_all",
"list_tokens_own",
"list_workload_policy",
"list_workload_pools",
"list_workload_rules",
"merge_buckets",
"metric_alerts",
"never_expire",
"never_lockout",
"output_file",
"pattern_detect",
"read_internal_libraries_settings",
"refresh_application_licenses",
"request_remote_tok",
"rest_access_server_endpoints",
"rest_apps_management",
"rest_apps_view",
"rest_properties_get",
"rest_properties_set",
"restart_reason",
"restart_splunkd",
"rtsearch",
"run_collect",
"run_commands_ignoring_field_filter",
"run_custom_command",
"run_debug_commands",
"run_dump",
"run_mcollect",
"run_msearch",
"run_sendalert",
"schedule_rtsearch",
"schedule_search",
"search",
"search_process_config_refresh",
"select_workload_pools",
"splunk_assist_admin",
"upload_lookup_files",
"upload_mmdb_files",
"use_file_operator",
"use_remote_proxy",
"web_debug"
],
"defaultApp": "launcher",
"defaultAppIsUserOverride": false,
"defaultAppSourceRole": "system",
"eai:acl": null,
"email": "example@blinkops.com",
"lang": "",
"last_successful_login": 1673771672,
"locked-out": false,
"password": "********",
"realname": "Administrator",
"restart_background_jobs": null,
"roles": [
"admin"
],
"search_assistant": "compact",
"search_auto_format": false,
"search_line_numbers": false,
"search_syntax_highlighting": "light",
"search_use_advanced_editor": true,
"theme": "enterprise",
"type": "Splunk",
"tz": ""
}
}
],
"paging": {
"total": 1,
"perPage": 30,
"offset": 0
},
"messages": []
}
Workflow Library Example
List Users with Splunk and Send Results Via Email
Preview this Workflow on desktop
Was this page helpful?
On this page