Security

Accidently removed permissions from only admin account

jmadsen1
Explorer

Hello, I recently messed up the permissions for the only account in my testing environment instance. I no longer have access to search my existing indexes and I cannot seem to re-grant admin level privileges to my account as I do not have the privileges to do so. I have tried to make another account but of course I am unable to give that account the permissions that I need. If there is anyway that I can restore my access please let me know.

Labels (2)
Tags (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

If you have revoke role from admin user you can just add it back to passwd file or maybe it's easier to remove that user from passwd and then recreate it as this https://docs.splunk.com/Documentation/Splunk/8.2.3/Security/Secureyouradminaccount

If you have revoke capabilities form role then, probably easiest way is remove etc/system/local/authorize.conf (take backup first if there is something special which you are needing later.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

If you have revoke role from admin user you can just add it back to passwd file or maybe it's easier to remove that user from passwd and then recreate it as this https://docs.splunk.com/Documentation/Splunk/8.2.3/Security/Secureyouradminaccount

If you have revoke capabilities form role then, probably easiest way is remove etc/system/local/authorize.conf (take backup first if there is something special which you are needing later.

r. Ismo

jmadsen1
Explorer

Isoutamo you are my hero, thank you so much!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...