Users
Query the users configured in Splunk and their properties.
Columns
| Name | Type | Description |
| Name [KEY] | String | The username of the Splunk user. |
| Id | String | The REST resource link for the user. |
| UpdatedAt | Datetime | Datetime of the last update of the user entry. |
| Author | String | The Splunk user that owns the user entry. |
| App | String | The Splunk app context where this user is shared. |
| CanList | Boolean | Indicates whether the user can be listed by the current user. |
| CanWrite | Boolean | Indicates whether the user can be modified by the current user. |
| Modifiable | Boolean | Indicates whether the user can be modified. |
| Owner | String | The owner of the user entry. |
| ReadPermissions | String | Permissions to read this user. |
| WritePermissions | String | Permissions to write to this user. |
| Removable | Boolean | Indicates whether the user can be removed. |
| Sharing | String | The user entry sharing type. |
| RealName | String | The full name of the user. |
| String | The email address of the user. | |
| Type | String | The authentication system type of the user. One of LDAP, Scripted, Splunk, or System. |
| Roles | String | The roles assigned to the user. |
| Capabilities | String | The list of capabilities assigned to the user through their roles. |
| DefaultApp | String | The default app for the user, which is invoked at login. |
| DefaultAppIsUserOverride | Boolean | Indicates whether the default app overrides the default app of the user role. |
| DefaultAppSourceRole | String | The role that determines the default app for the user, if the user has multiple roles. |
| LockedOut | Boolean | Indicates whether the user is locked out. |
| Password | String | The user password. Returned masked by the Splunk API. |
| LastSuccessfulLogin | Long | The epoch time, in seconds, of the last successful login of the user. |
| RestartBackgroundJobs | Boolean | Indicates whether to restart background search jobs that have not completed when Splunk restarts. |
| Tz | String | The timezone of the user. |
| Lang | String | The preferred language of the user. |
| Theme | String | The preferred UI theme of the user. |
| DisplayNewSearchBanner | Boolean | Indicates whether to display the new search banner for the user. |
| SearchAssistant | String | The search assistant mode preference of the user. |
| SearchAutoFormat | Boolean | Indicates whether search auto-formatting is enabled for the user. |
| SearchLineNumbers | Boolean | Indicates whether search line numbers are displayed for the user. |
| SearchSyntaxHighlighting | String | The search syntax highlighting preference of the user. |
| SearchUseAdvancedEditor | Boolean | Indicates whether the advanced search editor is enabled for the user. |