Security

Admin cannot change users' roles

bauron
Explorer

Under Splunk>Manager>>Access controls>>Users, I cannot assign/remove roles from the "Available roles" and "Selected roles" lists; all of the roles in both sections are greyed out and do not respond to clicks. The users are mapped to Splunk via LDAP and I've remapped groups multiple times.

I have repeatedly verified I am an admin user.

Tags (1)

somesoni2
Revered Legend

When you have configured authentication using LDAP, you can't modify User from Manager » Access controls » Users (role association). You would have to update the role association to the LDAP group (instead of user within the group) using LDAP strategies. See below documentation for steps:

http://docs.splunk.com/Documentation/Splunk/latest/Security/MapLDAPgroupstoSplunkroles

Other options is using authentication.conf file update.
http://docs.splunk.com/Documentation/Splunk/latest/Security/ConfigureLDAPwithconfigurationfiles

nick405060
Motivator

Had the same problem except nothing was greyed out, but instead whenever I removed a role from a LDAP user it would just revert back to having that role. Ended up deleting the role from the [rolemap_mycompany] stanza in authentication.conf in system/local and rebooted (not sure if needed) and that worked.

0 Karma

OldManEd
Builder

Does anyone have an answer for this one? I'm having the same issue with LDAP.

0 Karma

LukeMurphey
Champion

I'm not very familiar with using LDAP authentication in Splunk but I am familiar with using scripted authentication which is similar. With scripted authentication, the roles are expected to be provided by the authentication script and thus the roles editor is disabled in the manager. I suspect this is the same issue you are seeing here.

I opened an enhancement request asking for the ability to override the automatically defined roles. You may want to do the same.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...