Deployment Architecture

How to cleanup etc/users folder on search head cluster


I've got a lot of LDAP users who no longer exist (500+ folders in /etc/users). What's the proper way to clean this? If I just delete the folder won't the search head cluster just resync it from the captain's running configuration?

Also, someone pushed these using the Deployer when we migrated to 8.x. If I remove all user folders from the /etc/shcluster/users folder of the Deployer will anything bad happen next time I push? I have no desire to manage user settings with the Deployer; just push shcluster apps.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...