I found that if you look at either _internal index or the local splunkd.log, there's probably going to be more detail. In my case, it was a file permissions issue writing to $SPLUNK_HOME/etc/users/
I found that if you look at either _internal index or the local splunkd.log, there's probably going to be more detail. In my case, it was a file permissions issue writing to $SPLUNK_HOME/etc/users/