Security

Admin cannot change users' roles

bauron
Explorer

Under Splunk>Manager>>Access controls>>Users, I cannot assign/remove roles from the "Available roles" and "Selected roles" lists; all of the roles in both sections are greyed out and do not respond to clicks. The users are mapped to Splunk via LDAP and I've remapped groups multiple times.

I have repeatedly verified I am an admin user.

Tags (1)

somesoni2
Revered Legend

When you have configured authentication using LDAP, you can't modify User from Manager » Access controls » Users (role association). You would have to update the role association to the LDAP group (instead of user within the group) using LDAP strategies. See below documentation for steps:

http://docs.splunk.com/Documentation/Splunk/latest/Security/MapLDAPgroupstoSplunkroles

Other options is using authentication.conf file update.
http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureLDAPwithconfigurationfiles

nick405060
Motivator

Had the same problem except nothing was greyed out, but instead whenever I removed a role from a LDAP user it would just revert back to having that role. Ended up deleting the role from the [rolemap_mycompany] stanza in authentication.conf in system/local and rebooted (not sure if needed) and that worked.

0 Karma

OldManEd
Builder

Does anyone have an answer for this one? I'm having the same issue with LDAP.

0 Karma

LukeMurphey
Champion

I'm not very familiar with using LDAP authentication in Splunk but I am familiar with using scripted authentication which is similar. With scripted authentication, the roles are expected to be provided by the authentication script and thus the roles editor is disabled in the manager. I suspect this is the same issue you are seeing here.

I opened an enhancement request asking for the ability to override the automatically defined roles. You may want to do the same.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...