<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accidently removed permissions from only admin account in Security</title>
    <link>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576911#M15729</link>
    <description>&lt;P&gt;Isoutamo you are my hero, thank you so much!&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2021 14:58:09 GMT</pubDate>
    <dc:creator>jmadsen1</dc:creator>
    <dc:date>2021-12-01T14:58:09Z</dc:date>
    <item>
      <title>Accidently removed permissions from only admin account</title>
      <link>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576888#M15727</link>
      <description>&lt;P&gt;Hello, I recently messed up the permissions for the only account in my testing environment instance. I no longer have access to search my existing indexes and I cannot seem to re-grant admin level privileges to my account as I do not have the privileges to do so. I have tried to make another account but of course I am unable to give that account the permissions that I need. If there is anyway that I can restore my access please let me know.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 12:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576888#M15727</guid>
      <dc:creator>jmadsen1</dc:creator>
      <dc:date>2021-12-01T12:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Accidently removed permissions from only admin account</title>
      <link>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576904#M15728</link>
      <description>&lt;P&gt;If you have revoke role from admin user you can just add it back to passwd file or maybe it's easier to remove that user from passwd and then recreate it as this&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/Security/Secureyouradminaccount" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/Security/Secureyouradminaccount&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you have revoke capabilities form role then, probably easiest way is remove etc/system/local/authorize.conf (take backup first if there is something special which you are needing later.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 14:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576904#M15728</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-01T14:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Accidently removed permissions from only admin account</title>
      <link>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576911#M15729</link>
      <description>&lt;P&gt;Isoutamo you are my hero, thank you so much!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 14:58:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Accidently-removed-permissions-from-only-admin-account/m-p/576911#M15729</guid>
      <dc:creator>jmadsen1</dc:creator>
      <dc:date>2021-12-01T14:58:09Z</dc:date>
    </item>
  </channel>
</rss>

