Hi,
Does anyone know a Splunk search that when executed returns a list of all users that have access to Splunk via LDAP authentication?
I imagine that this info can possibly be extracted from one of the internal indexes in Splunk.
| rest /servicesNS/-/-/authentication/users | search type=LDAP