Splunk search for List of Users by Splunk Role
Copy
| rest splunk_server=local /services/authentication/users | table title roles
This Splunk search will show you a list of users that exist on the Search Head (or Search Head Cluster) that it is run on, along with the roles they are assigned to. If it is run by an administrator it will list all users, if it is run by someone that is not an administrator it will list the current users role only. Append | search title=username to search for a specific user.