<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354482#M8885</link>
    <description>&lt;P&gt;Hi @lycollicott,&lt;/P&gt;

&lt;P&gt;Thank you for your answer!&lt;BR /&gt;
That sounds like a good workaround.&lt;/P&gt;

&lt;P&gt;I didn't investigate this error any further, as it isn't really a 'problem'.&lt;/P&gt;

&lt;P&gt;Do you have already an update on this?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jun 2018 13:32:49 GMT</pubDate>
    <dc:creator>DennisWoerner</dc:creator>
    <dc:date>2018-06-28T13:32:49Z</dc:date>
    <item>
      <title>How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354476#M8879</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;

&lt;P&gt;After changing our authentication system from LDAP to SAML we get a lot of messages like this in splunkd.log:&lt;/P&gt;

&lt;P&gt;11-07-2017 18:35:00.904 +0100 WARN  UserManagerPro - AQR not supported and user=system information not found in cache&lt;/P&gt;

&lt;P&gt;All I could find out by myself is, that "AQR" is likely to mean "Assessor qualification &amp;amp; requirements" and it has something to do with SAML.&lt;/P&gt;

&lt;P&gt;Can anybody help here?&lt;/P&gt;

&lt;P&gt;Greetings&lt;BR /&gt;
Dennis&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 18:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354476#M8879</guid>
      <dc:creator>DennisFFM</dc:creator>
      <dc:date>2017-11-07T18:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354477#M8880</link>
      <description>&lt;P&gt;it might be worth opening a case with Splunk Support.  Looks like someone else is seeing this recently as well&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/588332/what-is-aqr-and-why-is-it-throwing-warning-message-1.html"&gt;https://answers.splunk.com/answers/588332/what-is-aqr-and-why-is-it-throwing-warning-message-1.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 15:17:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354477#M8880</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-11T15:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354478#M8881</link>
      <description>&lt;P&gt;AQR= attributeQueryRequest&lt;/P&gt;

&lt;P&gt;I'm actually on a webex with Splunk Support on this very thing right now.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 19:22:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354478#M8881</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2018-01-25T19:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354479#M8882</link>
      <description>&lt;P&gt;Dennis, we've been trying to figure this out for a while now and I've had a few Webex on it.  The analyst and I think it's probably a bug and probably harmless, but we might also have a temporary workaround.&lt;/P&gt;

&lt;P&gt;We created a local splunk user called system and gave it a weak role ....those messages ended immediately.  I'll keep you updated.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 19:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354479#M8882</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2018-01-25T19:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354480#M8883</link>
      <description>&lt;P&gt;So did you ever get an answer, @lycollicott?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 13:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354480#M8883</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-06-28T13:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354481#M8884</link>
      <description>&lt;P&gt;That is what we did as well as a workaround, lycollicott&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 13:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354481#M8884</guid>
      <dc:creator>scannon4</dc:creator>
      <dc:date>2018-06-28T13:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354482#M8885</link>
      <description>&lt;P&gt;Hi @lycollicott,&lt;/P&gt;

&lt;P&gt;Thank you for your answer!&lt;BR /&gt;
That sounds like a good workaround.&lt;/P&gt;

&lt;P&gt;I didn't investigate this error any further, as it isn't really a 'problem'.&lt;/P&gt;

&lt;P&gt;Do you have already an update on this?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 13:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354482#M8885</guid>
      <dc:creator>DennisWoerner</dc:creator>
      <dc:date>2018-06-28T13:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354483#M8886</link>
      <description>&lt;P&gt;Nothing beyond the workaround. &lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 19:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354483#M8886</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2018-07-09T19:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?</title>
      <link>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354484#M8887</link>
      <description>&lt;P&gt;There is nothing new to report on this, but the workaround is still in place.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 19:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-do-you-resolve-splunk-log-error-messages-after-switching/m-p/354484#M8887</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2018-07-09T19:16:59Z</dc:date>
    </item>
  </channel>
</rss>

