<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error in Splunkd.log: UserManagerPro - Failed to LDAP user -- for a deleted user! in Security</title>
    <link>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124907#M3802</link>
    <description>&lt;P&gt;In my splunkd.log, these messages repeat constantly (several times per minute). I turned on INFO-level logging to see if the extra information is useful. This user, "bnorthway", is an OS user (Linux), but not an LDAP user. There also used to be a Splunk (non-LDAP) user, but this account has been deleted. &lt;/P&gt;

&lt;P&gt;Why is Splunk trying to find this account on the LDAP server? How can I stop this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR AuthenticationManagerLDAP - Could not find user="bnorthway" with strategy="&amp;lt;domain&amp;gt;"
ERROR UserManagerPro - Failed to get LDAP user="bnorthway" from any configured servers
INFO  UserManagerPro - No user context available while checking capability=, auditInfo=""
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 28 May 2015 15:39:49 GMT</pubDate>
    <dc:creator>bnorthway</dc:creator>
    <dc:date>2015-05-28T15:39:49Z</dc:date>
    <item>
      <title>Error in Splunkd.log: UserManagerPro - Failed to LDAP user -- for a deleted user!</title>
      <link>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124907#M3802</link>
      <description>&lt;P&gt;In my splunkd.log, these messages repeat constantly (several times per minute). I turned on INFO-level logging to see if the extra information is useful. This user, "bnorthway", is an OS user (Linux), but not an LDAP user. There also used to be a Splunk (non-LDAP) user, but this account has been deleted. &lt;/P&gt;

&lt;P&gt;Why is Splunk trying to find this account on the LDAP server? How can I stop this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR AuthenticationManagerLDAP - Could not find user="bnorthway" with strategy="&amp;lt;domain&amp;gt;"
ERROR UserManagerPro - Failed to get LDAP user="bnorthway" from any configured servers
INFO  UserManagerPro - No user context available while checking capability=, auditInfo=""
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 28 May 2015 15:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124907#M3802</guid>
      <dc:creator>bnorthway</dc:creator>
      <dc:date>2015-05-28T15:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunkd.log: UserManagerPro - Failed to LDAP user -- for a deleted user!</title>
      <link>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124908#M3803</link>
      <description>&lt;P&gt;As per the documentation, Splunk will check against all configured access strategies. By default, it searches Splunk local users first and then any other strategy configured. &lt;BR /&gt;
(Ref: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureSplunkToUsePAMOrRADIUSAuthentication"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureSplunkToUsePAMOrRADIUSAuthentication&lt;/A&gt; )&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2015 00:50:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124908#M3803</guid>
      <dc:creator>sk314</dc:creator>
      <dc:date>2015-05-29T00:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunkd.log: UserManagerPro - Failed to LDAP user -- for a deleted user!</title>
      <link>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124909#M3804</link>
      <description>&lt;P&gt;Where would I find the configuration that is attempting to find this user?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 14:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124909#M3804</guid>
      <dc:creator>bnorthway</dc:creator>
      <dc:date>2015-09-24T14:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunkd.log: UserManagerPro - Failed to LDAP user -- for a deleted user!</title>
      <link>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124910#M3805</link>
      <description>&lt;P&gt;If the user bnorthway owns/created any Splunk artifacts ( like scheduled searches, alerts, etc) , you can change the ownership from bnorthway to nobody.&lt;/P&gt;

&lt;P&gt;For example: To change the ownership for searches owned/created by bnorthway&lt;BR /&gt;
Search for the user in &lt;STRONG&gt;local.meta&lt;/STRONG&gt; under &lt;STRONG&gt;$SPLUNK_HOME/etc/apps/search/metadata/&lt;/STRONG&gt; &lt;BR /&gt;
replace all occurrences of &lt;STRONG&gt;owner = bnorthway&lt;/STRONG&gt; to &lt;STRONG&gt;owner=nobody&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 20:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-in-Splunkd-log-UserManagerPro-Failed-to-LDAP-user-for-a/m-p/124910#M3805</guid>
      <dc:creator>rajanala</dc:creator>
      <dc:date>2016-02-09T20:59:02Z</dc:date>
    </item>
  </channel>
</rss>

