REST API: Table all Splunk User Email Addresses

The following simple Splunk query will put all Splunk User accounts with an email address into a panel for copy and paste purposes (such as copying all email addresses to send in an email). I’ve added a semi colon delimiter in order to literally be copy and paste into an application such as Microsoft Outlook.

| rest /services/authentication/users | search email!="" | dedup email| stats count by email | mvcombine delim=";" email | nomv email | fields - count | rename email as "Email Addresses"
Share This:

Leave A Comment?