<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scripted SSO auth errors on indexer cluster in Security</title>
    <link>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403534#M9759</link>
    <description>&lt;P&gt;We have a clustered setup with server types including an indexer cluster, a search head cluster, and a separate cluster master.&lt;/P&gt;

&lt;P&gt;We've implemented SSO with an auth script, but still receive messages from our indexers in splunkd.log to the effect of: &lt;CODE&gt;ERROR AuthenticationManagerScripted - Script function getUserInfo failed for user: nobody&lt;/CODE&gt;. How can I get rid of this? Is this an indication of failed functionality when searches are executed by the (internal) &lt;CODE&gt;nobody&lt;/CODE&gt; user?&lt;/P&gt;

&lt;P&gt;We also see these for bot users, which are local Splunk accounts in the search head cluster. Do I need to ensure these users exist on the indexer cluster as well?&lt;/P&gt;</description>
    <pubDate>Fri, 18 May 2018 02:51:14 GMT</pubDate>
    <dc:creator>krisreeves</dc:creator>
    <dc:date>2018-05-18T02:51:14Z</dc:date>
    <item>
      <title>Scripted SSO auth errors on indexer cluster</title>
      <link>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403534#M9759</link>
      <description>&lt;P&gt;We have a clustered setup with server types including an indexer cluster, a search head cluster, and a separate cluster master.&lt;/P&gt;

&lt;P&gt;We've implemented SSO with an auth script, but still receive messages from our indexers in splunkd.log to the effect of: &lt;CODE&gt;ERROR AuthenticationManagerScripted - Script function getUserInfo failed for user: nobody&lt;/CODE&gt;. How can I get rid of this? Is this an indication of failed functionality when searches are executed by the (internal) &lt;CODE&gt;nobody&lt;/CODE&gt; user?&lt;/P&gt;

&lt;P&gt;We also see these for bot users, which are local Splunk accounts in the search head cluster. Do I need to ensure these users exist on the indexer cluster as well?&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 02:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403534#M9759</guid>
      <dc:creator>krisreeves</dc:creator>
      <dc:date>2018-05-18T02:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted SSO auth errors on indexer cluster</title>
      <link>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403535#M9760</link>
      <description>&lt;P&gt;Can you test this script:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Security/Createtheauthenticationscript#Test_the_script"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Security/Createtheauthenticationscript#Test_the_script&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 03:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403535#M9760</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-05-18T03:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted SSO auth errors on indexer cluster</title>
      <link>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403536#M9761</link>
      <description>&lt;P&gt;The script works fine, but fails for the user "nobody", since that is not a SSO user. It's a special Splunk user / the lack of a user. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.4/DistSearch/Whatsearchheadssend#User_authorization"&gt;The docs&lt;/A&gt; state that the search heads send the authorization information to the peers at search time, so I'm not expecting this script to be run on search peers at all.&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 15:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Scripted-SSO-auth-errors-on-indexer-cluster/m-p/403536#M9761</guid>
      <dc:creator>krisreeves</dc:creator>
      <dc:date>2018-05-18T15:11:40Z</dc:date>
    </item>
  </channel>
</rss>

