Security

AuthenticationManagerLDAP Error Message and BaseDN setting

asarolkar
Builder

Hi All,

We are currently getting the following error

ERROR AuthenticationManagerLDAP - Could not find user="nobody" with strategy="LDAP DC02"
host=something

Not sure what error is causing this error.

Is it a known error message that appears when Splunk does not successfully bind to AD?
Is it a LDAP-role mapping issue ?
Should I perhaps be looking at BaseDN/groupbaseDN configuration ?

The user "nobody" looks a bit suspicious.

Tags (2)

NageswariV
Engager

HI, I find the same error with some of my users as well. how to resolve this issue? please help.

0 Karma

lmyrefelt
Builder

1.No
2. No, not really
3. No

I found dshpritz answer here helpfull;
http://answers.splunk.com/answers/49525/splunkdlog-error-message
Running; find /path/to/splunk/apps -iname *.meta -exec grep -il "nobody" {} ; gives me all objects owned by nobody and thus i can easily change it to an more appropriate context / user .
Hope it helps 🙂

lmyrefelt
Builder
  1. No
  2. No, not really
  3. No

I found dshpritz answer here helpfull;
http://answers.splunk.com/answers/49525/splunkdlog-error-message

Running; find /path/to/splunk/apps -iname *.meta -exec grep -il "nobody" {} \; gives me all objects owned by nobody and thus i can easily change it to an more appropriate context / user .

Hope it helps 🙂

0 Karma

xzjc3q
Explorer

I have the same issue as well. Would be interested in an answer.

0 Karma

gadjet
New Member

The user 'nobody' is supposed to be for 'configuration items' that aren't assigned a user.

I'm experiencing the same errors, and I would also like to know why it occurs, and how to stop it.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...