Getting Data In

Getting an error in checking authentication.conf

gekoner
Communicator

We are getting the following error on one of our Search Heads.
Splunk ver = 4.2.3
This happens when we run the "splunk btool check --debug" command.
Any ideas what we messed up? I think this is a bug.

Possible typo in stanza [roleMap] in /opt/splunk/etc/.... line **: user = SplunkAdmin

Tags (3)
0 Karma

seanwong
Explorer

It sounds to me like you have defined a custom group called SplunkAdmin with a specific privilege level that "user" is assigned to.

Can you check your authorize.conf and see if stanza along the lines of
[role_SplunkAdmin]

Did this happen after a splunk upgrade? If it did, you may want to open up a case with splunk and get a splunkdiag going.

0 Karma

gekoner
Communicator

I do not have a [role_SplunkAdmin] entry in authorize.conf
This didn't happen after an upgrade perse, but this might have been an issue since we upgraded to 4.2.x

Isn't the issue with the [roleMap] syntax?

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...