Getting Data In

Getting an error in checking authentication.conf

gekoner
Communicator

We are getting the following error on one of our Search Heads.
Splunk ver = 4.2.3
This happens when we run the "splunk btool check --debug" command.
Any ideas what we messed up? I think this is a bug.

Possible typo in stanza [roleMap] in /opt/splunk/etc/.... line **: user = SplunkAdmin

Tags (3)
0 Karma

seanwong
Explorer

It sounds to me like you have defined a custom group called SplunkAdmin with a specific privilege level that "user" is assigned to.

Can you check your authorize.conf and see if stanza along the lines of
[role_SplunkAdmin]

Did this happen after a splunk upgrade? If it did, you may want to open up a case with splunk and get a splunkdiag going.

0 Karma

gekoner
Communicator

I do not have a [role_SplunkAdmin] entry in authorize.conf
This didn't happen after an upgrade perse, but this might have been an issue since we upgraded to 4.2.x

Isn't the issue with the [roleMap] syntax?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...