<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unknown error message from Admin Manager in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365596#M165317</link>
    <description>&lt;P&gt;Sometimes I see errors like this if Splunk was started/stopped by root, when it normally runs as a different user. Some of the files become owned by root and then odd things don't work. In Linux, there is a simple fix. Assuming that&lt;/P&gt;

&lt;P&gt;Splunk is installed in /opt/splunk&lt;/P&gt;

&lt;P&gt;Splunk should run as user splunkit&lt;/P&gt;

&lt;P&gt;you are signed in as a user with sudo privileges&lt;/P&gt;

&lt;P&gt;cd /opt sudo chown -R splunkit splunk&lt;/P&gt;

&lt;P&gt;Of course, the problem could be something entirely different...&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2017 09:50:16 GMT</pubDate>
    <dc:creator>mayurr98</dc:creator>
    <dc:date>2017-11-10T09:50:16Z</dc:date>
    <item>
      <title>Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365593#M165314</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;has anyone seen the error message below?&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;ERROR&amp;nbsp;AdminManager&amp;nbsp;-&amp;nbsp;Argument&amp;nbsp;"actual_only"&amp;nbsp;is&amp;nbsp;not&amp;nbsp;supported&amp;nbsp;by&amp;nbsp;this&amp;nbsp;handler.
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Any ideas what may cause this?&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
Andy&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:16:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365593#M165314</guid>
      <dc:creator>kochera</dc:creator>
      <dc:date>2017-11-10T09:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365594#M165315</link>
      <description>&lt;P&gt;what is the impact of this error on your system?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365594#M165315</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2017-11-10T09:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365595#M165316</link>
      <description>&lt;P&gt;we don't know. it just generates a lot of error messages in the splunkd.log&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:25:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365595#M165316</guid>
      <dc:creator>kochera</dc:creator>
      <dc:date>2017-11-10T09:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365596#M165317</link>
      <description>&lt;P&gt;Sometimes I see errors like this if Splunk was started/stopped by root, when it normally runs as a different user. Some of the files become owned by root and then odd things don't work. In Linux, there is a simple fix. Assuming that&lt;/P&gt;

&lt;P&gt;Splunk is installed in /opt/splunk&lt;/P&gt;

&lt;P&gt;Splunk should run as user splunkit&lt;/P&gt;

&lt;P&gt;you are signed in as a user with sudo privileges&lt;/P&gt;

&lt;P&gt;cd /opt sudo chown -R splunkit splunk&lt;/P&gt;

&lt;P&gt;Of course, the problem could be something entirely different...&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 09:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365596#M165317</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2017-11-10T09:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365597#M165318</link>
      <description>&lt;P&gt;I checked on that already. the permissions are ok. &lt;BR /&gt;
we get the error on all SH-cluster members although not equally spreaded.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 10:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365597#M165318</guid>
      <dc:creator>kochera</dc:creator>
      <dc:date>2017-11-10T10:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365598#M165319</link>
      <description>&lt;P&gt;We have the same issue since the upgrade to 6.6.4&lt;BR /&gt;
Same error message.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 08:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365598#M165319</guid>
      <dc:creator>florho</dc:creator>
      <dc:date>2017-12-12T08:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365599#M165320</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/2090"&gt;@kochera&lt;/a&gt; we solved this issue by enabling the permissions&lt;BR /&gt;
list_accelerate_search &lt;BR /&gt;
for the users generating some errors.&lt;/P&gt;

&lt;P&gt;As from what we could see, splunk was trying to see if the search had summaries, but user running the search did not have permission to check this.&lt;/P&gt;

&lt;P&gt;Thanks to Maarten &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/44632"&gt;@mhoogcarspel_sp&lt;/a&gt;lunk  from support for pointing in the right direction.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365599#M165320</guid>
      <dc:creator>florho</dc:creator>
      <dc:date>2020-09-29T17:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365600#M165321</link>
      <description>&lt;P&gt;Specifically, we found this in the audit log, you can check with this, in the timeframe of the error:&lt;/P&gt;

&lt;P&gt;index=_audit action=&lt;EM&gt;accelerate_search&lt;/EM&gt;&lt;BR /&gt;
| stats values(info) values(action) BY user&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:01:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365600#M165321</guid>
      <dc:creator>mhoogcarspel_sp</dc:creator>
      <dc:date>2020-09-29T18:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unknown error message from Admin Manager</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365601#M165322</link>
      <description>&lt;P&gt;This worked - thx&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 20:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unknown-error-message-from-Admin-Manager/m-p/365601#M165322</guid>
      <dc:creator>pj</dc:creator>
      <dc:date>2018-02-09T20:01:31Z</dc:date>
    </item>
  </channel>
</rss>

