Getting Data In

After upgrade to 6.5.0, why is my indexer reporting "ERROR UserManagerPro - Could not get info for non-existent user"?

ateterine
Path Finder

Hi Splunkers,

Haven't seen this message prior to 6.5 update, but now splunkd.log is full of it.

Any idea why it might be happening?

11-17-2016 14:52:08.837 -0800 WARN  IniFile - C:\Program Files\Splunk\var\run\searchpeers\bpsplunk-mstr-1479423126\apps\splunk_monitoring_console\metadata\local.meta, line 13: Cannot parse into key-value pair:       
11-17-2016 14:52:08.841 -0800 WARN  IniFile - C:\Program Files\Splunk\var\run\searchpeers\bpsplunk-mstr-1479423126\apps\learned\metadata\local.meta, line 17: Cannot parse into key-value pair:         
11-17-2016 14:52:19.555 -0800 ERROR UserManagerPro - Could not get info for non-existent user="username"
1
Tags (3)
0 Karma

swaro_ck
Path Finder

Hi, in the meantime I got an answer from Splunk Support, they will fix it in 6.5.3

Murali2888
Communicator

Hi swaro_ck,

Did we happen to get details on what the issue is?

0 Karma

swaro_ck
Path Finder

They just told me that the problem was fixed in 6.5.3 and after the update the message was gone. I got no details what exactly the problem was.

0 Karma

gjanders
SplunkTrust
SplunkTrust

I am getting

ERROR UserManagerPro - Failed to get LDAP user="XXX" from any configured servers
ERROR AuthenticationManagerLDAP - user="XXX" has matching LDAP groups with strategy="ldap"

but none are mapped to Splunk roles

After the 6.5 upgrade, is that similar or different to what you are seeing ?

teunlaan
Contributor

Have the same problem (6.5.1 and 6.5.2)
I noticed it only happens when we are running Real-time searches

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...