<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer Cluster user=&amp;quot;&amp;quot; had no roles in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707131#M21149</link>
    <description>&lt;P&gt;Sorry for had being annoying, I'm stopping this behavior.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Dec 2024 09:00:24 GMT</pubDate>
    <dc:creator>NoSpaces</dc:creator>
    <dc:date>2024-12-18T09:00:24Z</dc:date>
    <item>
      <title>Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/700999#M20413</link>
      <description>&lt;P&gt;Hello to everyone!&lt;BR /&gt;Today I noticed strange messages in the daily warn and errors report:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;10-04-2024 16:55:01.935 +0300 WARN  UserManagerPro [5280 indexerPipe_0] - Unable to get roles for user= because: Could not get info for non-existent user=""
10-04-2024 16:55:01.935 +0300 ERROR UserManagerPro [5280 indexerPipe_0] - user="" had no roles&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked that this couple first appeared 5 days ago, but this fact can't help me because I don't remember what I changed in the exact day.&lt;BR /&gt;I also tried to find some helpful "nearby" events that can help me to understand the root case, but didn't observe anything interesting.&lt;BR /&gt;Which ways do I have to investigate this case?&lt;BR /&gt;Maybe I can "rise" log policy to DEBUG lvl? If I can, what should I change and where?&lt;BR /&gt;&lt;BR /&gt;Little more information:&lt;BR /&gt;I have searchhead cluster with LDAP authorization&lt;BR /&gt;And also indexer cluster only with local users&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 08:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/700999#M20413</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-10-07T08:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/701274#M20451</link>
      <description>&lt;P&gt;Up&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 09:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/701274#M20451</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-10-08T09:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/702142#M20536</link>
      <description>&lt;P&gt;Up&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 07:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/702142#M20536</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-10-17T07:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/705473#M20941</link>
      <description>&lt;P&gt;Up&lt;BR /&gt;&lt;BR /&gt;A week ago, I tried to enable DEBUG log to find the root case&lt;BR /&gt;But found only the similar events without anything helpful to find the root case&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 10:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/705473#M20941</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-11-28T10:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707123#M21144</link>
      <description>&lt;P&gt;UP&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 08:26:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707123#M21144</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-12-18T08:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707129#M21147</link>
      <description>&lt;P&gt;Please stop UP-ing the thread. You haven't found a similar issue in old threads, noone seems to be able to help you here right now. It's time to engage support. Posting "UP" once a week only clutters the forum.&lt;/P&gt;&lt;P&gt;Thanks for understanding.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 08:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707129#M21147</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-18T08:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707131#M21149</link>
      <description>&lt;P&gt;Sorry for had being annoying, I'm stopping this behavior.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 09:00:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707131#M21149</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-12-18T09:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707202#M21155</link>
      <description>Have you check this &lt;A href="https://community.splunk.com/t5/Security/ERROR-UserManagerPro-user-quot-system-quot-had-no-roles/m-p/309029" target="_blank"&gt;https://community.splunk.com/t5/Security/ERROR-UserManagerPro-user-quot-system-quot-had-no-roles/m-p/309029&lt;/A&gt; ?</description>
      <pubDate>Wed, 18 Dec 2024 18:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707202#M21155</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-18T18:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707300#M21175</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;, Thank you for your attention to my problem.&lt;BR /&gt;I saw this post, and I also saw the resolution—create the user 'system'.&lt;BR /&gt;But my case is a little bit different because errors have no information about the user that is absent.&lt;BR /&gt;Only quotes without anything.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 15:12:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707300#M21175</guid>
      <dc:creator>NoSpaces</dc:creator>
      <dc:date>2024-12-19T15:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Cluster user="" had no roles</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707322#M21179</link>
      <description>Only thing what comes my mind is that you should try to find some matches from other logs including sh side, which process or query has initiated this query on indexer side and found more information over there.&lt;BR /&gt;Another option is create a support case to splunk.</description>
      <pubDate>Thu, 19 Dec 2024 18:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexer-Cluster-user-quot-quot-had-no-roles/m-p/707322#M21179</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-19T18:12:00Z</dc:date>
    </item>
  </channel>
</rss>

