Since I migrated splunk to version 9.2.4, I've been getting a lot of error messages from all Splunk servers :
WARN UserManagerPro [16791 SchedulerThread] - Unable to get roles for user=nobody because: Failed to get LDAP user=“nobody” from any configured servers
ERROR UserManagerPro [16791 SchedulerThread] - user=“nobody” had no roles
I think these are all scheduled searches that are executed without an owner and therefore executed as user nobody.
These messages didn't appear with version 9.1
What's the best way to turn off these messages?
The annoying thing is that some searches come from Splunk apps (console monitoring, splunk archiver, etc.)
Hi,
Did you find a fix besides reassinging all the savedsearches without a owner?
The behavior is very strange. To stop getting error messages, I had to reassign savedsearches to an existing admin account. The messages disappeared. It's a workaround.
But I get lots of similar messages when I navigate to the Scheduler Activity: Instance dashboard in the monitoring console:
01-06-2025 17:07:59.749 +0100 ERROR UserManagerPro [24247 TcpChannelThread] - user=“nobody” had no roles
Looks like a known issue for version 9.2