Security

Failsafe user working?

hcpr
Path Finder

Hi folks.

I have a Splunk setup to authenticate by LDAP, and this works reasonably well. Sometimes auth stops working for no apparent reason, and that's when this question becomes interesting.

I can't get the "failsafe" user in LDAP conf to work. Dos this function as intended for anyone? If so, how do i make it work? Currently any attempt to log on as the user listed as failsafe user in the LDAP config just returns the normal authentication failed message.

Any suggestions?

Tags (2)

the_wolverine
Champion

If you recently migrated to version 4.1.x, your failsafe user (as configured in authentication.conf) is disabled. The new failsafe user is "admin" and is accessible from the UI:

Manager >> Access Controls >> Users

The default password is "changeme" and can be changed from the UI as well.

Simeon
Splunk Employee
Splunk Employee

Please detail the version of Splunk you are using, as 4.0 differs from 4.1.

0 Karma

Simeon
Splunk Employee
Splunk Employee

You should check the splunkd.log for why the LDAP authentication fails. If all of the LDAP auth fails, then there is likely a problem with your connectivity to the system. You should ensure that you are not using an alias for the LDAP host and that your LDAP server is not returning referrals.

Additionally, if you manually copied the authentication configuration from another machine then you will need to re-enter the passwords so they are encrypted with the correct key.

Another possible condition is that your failsafe username exists in your LDAP system, thus causing a conflict. You should make sure the failsafe username is unique.

treinke
Builder

Which version of Splunk are you using? I am currently on 4.1.2 and you can have both local and ldap users in the Splunk system.

There are no answer without questions
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...