<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise upgrade to 9.1.0.1, all users disappeared in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650813#M16847</link>
    <description>&lt;P&gt;PickleRick, seems you were right, and thanks for the response.&amp;nbsp;&lt;BR /&gt;There was a bug reported in 2019, that in my opinion is back with v9.1.0.1. Reference:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Security/Admin-can-t-see-users-with-a-certain-role-and-we-can-t-take-out/m-p/399779" target="_self"&gt;https://community.splunk.com/t5/Security/Admin-can-t-see-users-with-a-certain-role-and-we-can-t-take-out/m-p/399779&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Adding all roles to 'grandableRoles' solved the problem.&amp;nbsp; Consider this a bug since the problem appeared immediately on several deployments, all unrelated to each other, that all worked fine immediately preceding upgrade.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2023 16:14:12 GMT</pubDate>
    <dc:creator>tlmayes</dc:creator>
    <dc:date>2023-07-17T16:14:12Z</dc:date>
    <item>
      <title>Splunk Enterprise upgrade to 9.1.0.1, all users disappeared</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650181#M16797</link>
      <description>&lt;P&gt;Upgraded several independent instances of Splunk Enterprise from various starting points, all to 9.1.0.1.&amp;nbsp; &amp;nbsp;Some clustered, some standalone.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;8.1 -&amp;gt; 9.1.0.1&lt;/LI&gt;&lt;LI&gt;9.0.1 -&amp;gt; 9.1.0.1&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;All had the same outcome:&amp;nbsp; When browsing to: Settings &amp;gt; Users and Authentication &amp;gt; Users, most but not all users are no longer visible in the 'Users' list, but the users still have access as validate by Splunk logs.&amp;nbsp; In the most severe case there were 100+ users, mostly SAML, some local.&amp;nbsp; Post upgrade there are 4 showing, yet in validation all can still login&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 13:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650181#M16797</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2023-07-12T13:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise upgrade to 9.1.0.1, all users disappeared</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650520#M16824</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/84018"&gt;@tlmayes&lt;/a&gt;&amp;nbsp;- I don't see any known issues, hence I would say create a Splunk support case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!! Consider upvoting!!!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 09:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650520#M16824</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-07-14T09:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise upgrade to 9.1.0.1, all users disappeared</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650560#M16825</link>
      <description>&lt;P&gt;I used to have a similar problem (but at some earlier version) due to wrong entries in authorize.conf&lt;/P&gt;&lt;P&gt;If I remember correctly, it had something to do with a role having set edit_roles_grantable privilege but not having defined grantableRoles parameter. User with such role would not show in the users list but would still be able to authenticate to web interface and use the system normally.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 13:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650560#M16825</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-07-14T13:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise upgrade to 9.1.0.1, all users disappeared</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650813#M16847</link>
      <description>&lt;P&gt;PickleRick, seems you were right, and thanks for the response.&amp;nbsp;&lt;BR /&gt;There was a bug reported in 2019, that in my opinion is back with v9.1.0.1. Reference:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Security/Admin-can-t-see-users-with-a-certain-role-and-we-can-t-take-out/m-p/399779" target="_self"&gt;https://community.splunk.com/t5/Security/Admin-can-t-see-users-with-a-certain-role-and-we-can-t-take-out/m-p/399779&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Adding all roles to 'grandableRoles' solved the problem.&amp;nbsp; Consider this a bug since the problem appeared immediately on several deployments, all unrelated to each other, that all worked fine immediately preceding upgrade.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 16:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-upgrade-to-9-1-0-1-all-users-disappeared/m-p/650813#M16847</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2023-07-17T16:14:12Z</dc:date>
    </item>
  </channel>
</rss>

