One of our Cyber security person facing a strange issue while trying to access the data from the Splunk search portal. Initial level of troubleshooting the issue we found that Roles/Permission are not syncing but later we found that Roles/Permission are auto changing frequently. We could not find any ERROR/WARN in the splunkd.log, so not sure how to troubleshoot this issue
Splunk version : 8.2
Authentication mode: LDAP
Environment: Splunk distributed Production Environment.
Problem statement: Roles/Permission are not syncing properly its getting auto changed frequently.
Kindly let me know what are steps we should follow to troubleshoot this type of issue.