<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk searches from deleted users in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-searches-from-deleted-users/m-p/93867#M3112</link>
    <description>&lt;P&gt;We can see in our splunkd.log that is showing the following errors:&lt;/P&gt;

&lt;P&gt;UserManagerPro - Failed to get LDAP user="xxx" from any configured servers&lt;BR /&gt;
AuthenticationManagerLDAP - user="xxx" has matching LDAP groups with strategy="yyyy", but none are mapped to Splunk roles&lt;/P&gt;

&lt;P&gt;We also get some error messages with 'user="splunk"', but have no user splunk. They are not the same as those run by splunk-system-user.&lt;/P&gt;

&lt;P&gt;These users were removed, and should not be running searches. Yet these messages are consistently being reported. We would like to know what searches they apply to, so we can disable the searches, or move them to another user. But the message does not say what searches are running, nor give us any information to go on. Any ideas?&lt;/P&gt;

&lt;P&gt;Richard Thomsen&lt;/P&gt;</description>
    <pubDate>Wed, 17 Oct 2012 21:19:25 GMT</pubDate>
    <dc:creator>rgtsplunk</dc:creator>
    <dc:date>2012-10-17T21:19:25Z</dc:date>
    <item>
      <title>Splunk searches from deleted users</title>
      <link>https://community.splunk.com/t5/Security/Splunk-searches-from-deleted-users/m-p/93867#M3112</link>
      <description>&lt;P&gt;We can see in our splunkd.log that is showing the following errors:&lt;/P&gt;

&lt;P&gt;UserManagerPro - Failed to get LDAP user="xxx" from any configured servers&lt;BR /&gt;
AuthenticationManagerLDAP - user="xxx" has matching LDAP groups with strategy="yyyy", but none are mapped to Splunk roles&lt;/P&gt;

&lt;P&gt;We also get some error messages with 'user="splunk"', but have no user splunk. They are not the same as those run by splunk-system-user.&lt;/P&gt;

&lt;P&gt;These users were removed, and should not be running searches. Yet these messages are consistently being reported. We would like to know what searches they apply to, so we can disable the searches, or move them to another user. But the message does not say what searches are running, nor give us any information to go on. Any ideas?&lt;/P&gt;

&lt;P&gt;Richard Thomsen&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2012 21:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-searches-from-deleted-users/m-p/93867#M3112</guid>
      <dc:creator>rgtsplunk</dc:creator>
      <dc:date>2012-10-17T21:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk searches from deleted users</title>
      <link>https://community.splunk.com/t5/Security/Splunk-searches-from-deleted-users/m-p/93868#M3113</link>
      <description>&lt;P&gt;you're most likely seeing saved searches created by these users that are run on a schedule. to see the owners of saved searches, you can look in Manager &amp;gt; Searches and reports. &lt;/P&gt;

&lt;P&gt;once there, you can use the search box on the right to look for those usernames, or filter by app. &lt;/P&gt;

&lt;P&gt;to change the owner of a search defined in $SPLUNK_HOME/etc/apps/search/local/savedsearches.conf, edit the ownership and permissions defined in etc/apps/search/metadata/local.meta.  you'll need to substitute the app name of any app you're working on for 'search'&lt;/P&gt;

&lt;P&gt;you will have to restart splunk to see the change. &lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2012 21:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-searches-from-deleted-users/m-p/93868#M3113</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2012-12-21T21:55:41Z</dc:date>
    </item>
  </channel>
</rss>

