<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrade to 9.1.2 all users try to execute &amp;quot;admin_all_objects&amp;quot; in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683836#M19103</link>
    <description>&lt;P&gt;I put a ticket into Splunk and found that its a "known" bug that is not in their normal KBDB but they will work to get it there, in the mean time per support and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/186025"&gt;@SierraX&lt;/a&gt;&amp;nbsp;confirming, upgrading to 9.1.3 resolved the issue.&amp;nbsp; I have requested if Splunk would be able to divulge what the bug was.&amp;nbsp; &amp;nbsp;Waiting for response.&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/186025"&gt;@SierraX&lt;/a&gt;&amp;nbsp;for your response... funny I got your response and Splunk support's response in at the same time... (Scary... LOL)&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2024 15:25:10 GMT</pubDate>
    <dc:creator>cmeisch</dc:creator>
    <dc:date>2024-04-10T15:25:10Z</dc:date>
    <item>
      <title>After upgrade to 9.1.2 all users try to execute "admin_all_objects"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/673195#M18242</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yesterday I upgraded a splunk instance from 8.2.6 to 9.1.2. Afterwards all users that have the role "user" are logging every 10 milliseconds this log:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;01-04-2024 08:53:44.220 +0000 INFO  AuditLogger - Audit:[timestamp=01-04-2024 08:53:44.220, user=test_user, action=admin_all_objects, info=denied ]&lt;/LI-CODE&gt;&lt;P&gt;This issue is filling the index _audit very fast and I had to reduce the index size as a workaround but I doesn't resolve the problem.&lt;BR /&gt;&lt;BR /&gt;Have you ever have these problem in your enviroment?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 09:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/673195#M18242</guid>
      <dc:creator>aguilard</dc:creator>
      <dc:date>2024-01-04T09:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 9.1.2 all users try to execute "admin_all_objects"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683644#M19091</link>
      <description>&lt;P&gt;In looking for an audit event we saw this behavior too... anyone else?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Did you get a response outside of your query?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 19:47:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683644#M19091</guid>
      <dc:creator>cmeisch</dc:creator>
      <dc:date>2024-04-08T19:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 9.1.2 all users try to execute "admin_all_objects"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683705#M19096</link>
      <description>&lt;P&gt;I just checked our Searchheads for this issue:&lt;BR /&gt;We had the same messages until we upgraded all Searchheads from 9.1.2 to 9.1.3.&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:10:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683705#M19096</guid>
      <dc:creator>SierraX</dc:creator>
      <dc:date>2024-04-09T15:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 9.1.2 all users try to execute "admin_all_objects"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683836#M19103</link>
      <description>&lt;P&gt;I put a ticket into Splunk and found that its a "known" bug that is not in their normal KBDB but they will work to get it there, in the mean time per support and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/186025"&gt;@SierraX&lt;/a&gt;&amp;nbsp;confirming, upgrading to 9.1.3 resolved the issue.&amp;nbsp; I have requested if Splunk would be able to divulge what the bug was.&amp;nbsp; &amp;nbsp;Waiting for response.&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/186025"&gt;@SierraX&lt;/a&gt;&amp;nbsp;for your response... funny I got your response and Splunk support's response in at the same time... (Scary... LOL)&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 15:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/683836#M19103</guid>
      <dc:creator>cmeisch</dc:creator>
      <dc:date>2024-04-10T15:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrade to 9.1.2 all users try to execute "admin_all_objects"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/691623#M19695</link>
      <description>&lt;P&gt;This is more of annoying log message issue. The log messages are intended to be suppressed and can be ignored unless it affects any Splunk performances in indexing or searching.&amp;nbsp; Fix versions, 9.1.3+, 9.2.0+&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 02:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/After-upgrade-to-9-1-2-all-users-try-to-execute-quot-admin-all/m-p/691623#M19695</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2024-06-26T02:37:02Z</dc:date>
    </item>
  </channel>
</rss>

