<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does the DMC setup fail when the admin account is renamed or deleted? in Security</title>
    <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253334#M6990</link>
    <description>&lt;P&gt;This issue has been identified as a product defect - internal reference: SPL-92633.&lt;/P&gt;

&lt;P&gt;The problem is quite simply that some DMC actions (typically, configuration changes) are hard-coded to run lookup-manipulating searches &lt;EM&gt;as the "admin" user&lt;/EM&gt;, which of course fails if the user in question has been renamed.&lt;/P&gt;

&lt;P&gt;The work-around (and actually, the fix too) is to leverage the &lt;CODE&gt;dispatchAs = user&lt;/CODE&gt; property in savedsearches.conf (new to 6.2) which allows a saved search to be run as the invoking user instead of the owning user when called.&lt;/P&gt;

&lt;P&gt;Work-around steps:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Add the &lt;CODE&gt;dispatchAs = user&lt;/CODE&gt; key to the &lt;CODE&gt;DMC Asset - Build Full&lt;/CODE&gt; saved search stanza in &lt;CODE&gt;$SPLUNK_HOME/etc/apps/splunk_management_console/local/savedsearches.conf&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Restart Splunk or hit the /debug/refresh UI endpoint&lt;/LI&gt;
&lt;LI&gt;Run DMC setup again&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 05 Oct 2015 19:50:39 GMT</pubDate>
    <dc:creator>hexx</dc:creator>
    <dc:date>2015-10-05T19:50:39Z</dc:date>
    <item>
      <title>Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253330#M6986</link>
      <description>&lt;P&gt;The DMC general setup does not work if you delete or rename the admin account (e.g. via user-seed.conf).&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/User-seedconf" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/User-seedconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In 6.2, the work-around is to change the owner = nobody for all knowledge objects within the metadata/local.meta file of the splunk_management_console app, and then executing a splunk restart or debug/refresh.&lt;/P&gt;

&lt;P&gt;In 6.3, this does not work.&lt;BR /&gt;
What is the work-around/fix for this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253330#M6986</guid>
      <dc:creator>mkolkebeck</dc:creator>
      <dc:date>2020-09-29T07:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253331#M6987</link>
      <description>&lt;P&gt;There was a specific issue with the DMC setup and renamed admin accounts that was fixed in 6.3. Can you describe in detail what interactions with the DMC are no longer working and how that manifests itself?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Oct 2015 22:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253331#M6987</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2015-10-04T22:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253332#M6988</link>
      <description>&lt;P&gt;When changing to a Distributed configuration and clicking Apply Changes (with no errors), the Modal screen fails to appear or apply any changes. Only after creating the 'admin' account, the changes apply as expected. Also, splunkd.log shows failed admin ldap logins.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 13:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253332#M6988</guid>
      <dc:creator>mkolkebeck</dc:creator>
      <dc:date>2015-10-05T13:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253333#M6989</link>
      <description>&lt;P&gt;Actually, I was wrong: The fix for this issue did &lt;EM&gt;not&lt;/EM&gt; make it into 6.3 which explains why you are still seeing it! I will explain how to work around this problem in an answer.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 19:44:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253333#M6989</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2015-10-05T19:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253334#M6990</link>
      <description>&lt;P&gt;This issue has been identified as a product defect - internal reference: SPL-92633.&lt;/P&gt;

&lt;P&gt;The problem is quite simply that some DMC actions (typically, configuration changes) are hard-coded to run lookup-manipulating searches &lt;EM&gt;as the "admin" user&lt;/EM&gt;, which of course fails if the user in question has been renamed.&lt;/P&gt;

&lt;P&gt;The work-around (and actually, the fix too) is to leverage the &lt;CODE&gt;dispatchAs = user&lt;/CODE&gt; property in savedsearches.conf (new to 6.2) which allows a saved search to be run as the invoking user instead of the owning user when called.&lt;/P&gt;

&lt;P&gt;Work-around steps:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Add the &lt;CODE&gt;dispatchAs = user&lt;/CODE&gt; key to the &lt;CODE&gt;DMC Asset - Build Full&lt;/CODE&gt; saved search stanza in &lt;CODE&gt;$SPLUNK_HOME/etc/apps/splunk_management_console/local/savedsearches.conf&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Restart Splunk or hit the /debug/refresh UI endpoint&lt;/LI&gt;
&lt;LI&gt;Run DMC setup again&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 05 Oct 2015 19:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253334#M6990</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2015-10-05T19:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253335#M6991</link>
      <description>&lt;P&gt;Thanks hexx. Unfortunately, this workaround/fix did not work for me.&lt;/P&gt;

&lt;P&gt;I made the changes per your steps (and removed my local.meta changes), but I continue to get ldap calls for the admin user, and the modal screen does not appear.  I also added dispatchAs = user to all of the savedsearches stanzas that are in default, but same thing happened.  I even went so far as to add dispatchAs = user to a default stanza in this savedsearches.conf, but still no luck.  Also, changing the owner in local.meta to a renamed admin account does not work.  Lastly, I removed LDAP authentication, and that did not help.&lt;/P&gt;

&lt;P&gt;In addition, the Forwarder Monitoring Setup page does not load when the "admin" user account does not exist.&lt;/P&gt;

&lt;P&gt;So far, the only thing that has worked for me is to temporarily add a local "admin" user account.&lt;/P&gt;

&lt;P&gt;Is there a log.cfg setting that I can set to DEBUG the calls to which populating lookup search is run, and by what user?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2015 01:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253335#M6991</guid>
      <dc:creator>mkolkebeck</dc:creator>
      <dc:date>2015-10-06T01:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253336#M6992</link>
      <description>&lt;P&gt;Create a new "admin" user account and assign it to a new role that has no privileges.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2015 01:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253336#M6992</guid>
      <dc:creator>mkolkebeck</dc:creator>
      <dc:date>2015-10-06T01:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the DMC setup fail when the admin account is renamed or deleted?</title>
      <link>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253337#M6993</link>
      <description>&lt;P&gt;I'm sorry to hear this suggested work-around did not function. I would like to strongly encourage you to open a support case so that we can look into this issue in more detail and identify if there is a new defect to be fixed here.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2015 03:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-does-the-DMC-setup-fail-when-the-admin-account-is-renamed-or/m-p/253337#M6993</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2015-10-06T03:50:39Z</dc:date>
    </item>
  </channel>
</rss>

