<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting an error in checking authentication.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49931#M9487</link>
    <description>&lt;P&gt;We are getting the following error on one of our Search Heads.&lt;BR /&gt;
Splunk ver = 4.2.3&lt;BR /&gt;
This happens when we run the "splunk btool check --debug" command.&lt;BR /&gt;
Any ideas what we messed up? I think this is a bug.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Possible typo in stanza [roleMap] in /opt/splunk/etc/.... line **: user = SplunkAdmin&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Nov 2012 23:49:51 GMT</pubDate>
    <dc:creator>gekoner</dc:creator>
    <dc:date>2012-11-29T23:49:51Z</dc:date>
    <item>
      <title>Getting an error in checking authentication.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49931#M9487</link>
      <description>&lt;P&gt;We are getting the following error on one of our Search Heads.&lt;BR /&gt;
Splunk ver = 4.2.3&lt;BR /&gt;
This happens when we run the "splunk btool check --debug" command.&lt;BR /&gt;
Any ideas what we messed up? I think this is a bug.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Possible typo in stanza [roleMap] in /opt/splunk/etc/.... line **: user = SplunkAdmin&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 23:49:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49931#M9487</guid>
      <dc:creator>gekoner</dc:creator>
      <dc:date>2012-11-29T23:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Getting an error in checking authentication.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49932#M9488</link>
      <description>&lt;P&gt;It sounds to me like you have defined a custom group called SplunkAdmin with a specific privilege level that "user" is assigned to. &lt;/P&gt;

&lt;P&gt;Can you check your authorize.conf and see if stanza along the lines of&lt;BR /&gt;
&lt;CODE&gt;[role_SplunkAdmin]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Did this happen after a splunk upgrade? If it did, you may want to open up a case with splunk and get a splunkdiag going. &lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 00:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49932#M9488</guid>
      <dc:creator>seanwong</dc:creator>
      <dc:date>2012-11-30T00:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Getting an error in checking authentication.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49933#M9489</link>
      <description>&lt;P&gt;I do not have a [role_SplunkAdmin] entry in authorize.conf&lt;BR /&gt;
This didn't happen after an upgrade perse, but this might have been an issue since we upgraded to 4.2.x&lt;/P&gt;

&lt;P&gt;Isn't the issue with the [roleMap] syntax?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 00:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-an-error-in-checking-authentication-conf/m-p/49933#M9489</guid>
      <dc:creator>gekoner</dc:creator>
      <dc:date>2012-11-30T00:27:20Z</dc:date>
    </item>
  </channel>
</rss>

