Splunk Search

Not able to access splunk

gajananh999
Contributor

Dear All,

We have splunk search head with 100's of user in it. But suddenly this morning what happened i dont know but none of user is not able to login. I can only login with Splunk admin account may i know what is the issue for this?

Thanks
Gajanan

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

What happens when you log in as local admin user and go to Settings -> Authentication -> Authentication Method -> Configure ... LDAP ... groups -> Your LDAP Strategy -> Map Groups?

My working hypothesis is that your Splunk instance cannot connect with your LDAP for some reason.

0 Karma

jimodonald
Contributor

Check to see if the service account is locked out on the LDAP server.

gajananh999
Contributor

No one able to login. its Windows machine with splunk 6.0.2

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Sounds like that's your problem. Check the user exists obviously, and that Splunk can connect to the server.

What version are you using, and on what OS?

0 Karma

gajananh999
Contributor

Martin.. 07-15-2014 06:23:33.216 -0400 ERROR UserManagerPro - Failed to get LDAP user="m8000" from any configured servers

0 Karma

gajananh999
Contributor

Dear Martin its working fine its giving me a result.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Oops, try *LDAP*. Alternatively, take the time of a failed attempt and look at everything that happened around that time.

0 Karma

gajananh999
Contributor

index=_internal LDAP* its not giving any result..

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Check if that's working as it should.

For example, search the _internal index for LDAP*.

0 Karma

gajananh999
Contributor

Yes we use LDAP

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

So the licensing page tells you your license is valid? Great.

Do you use external authentication, such as LDAP/AD/etc.?

0 Karma

gajananh999
Contributor

Thanks for your reply.There is No licensing alerts.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Check your license messages. Either click Messages if nobody deleted them yet, or go to Settings -> Licensing and see what that says.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...