Security

How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?

DennisFFM
Explorer

Hey guys,

After changing our authentication system from LDAP to SAML we get a lot of messages like this in splunkd.log:

11-07-2017 18:35:00.904 +0100 WARN UserManagerPro - AQR not supported and user=system information not found in cache

All I could find out by myself is, that "AQR" is likely to mean "Assessor qualification & requirements" and it has something to do with SAML.

Can anybody help here?

Greetings
Dennis

lycollicott
Motivator

Dennis, we've been trying to figure this out for a while now and I've had a few Webex on it. The analyst and I think it's probably a bug and probably harmless, but we might also have a temporary workaround.

We created a local splunk user called system and gave it a weak role ....those messages ended immediately. I'll keep you updated.

DennisWoerner
Explorer

Hi @lycollicott,

Thank you for your answer!
That sounds like a good workaround.

I didn't investigate this error any further, as it isn't really a 'problem'.

Do you have already an update on this?

0 Karma

lycollicott
Motivator

There is nothing new to report on this, but the workaround is still in place.

0 Karma

scannon4
Communicator

That is what we did as well as a workaround, lycollicott

0 Karma

woodcock
Esteemed Legend

So did you ever get an answer, @lycollicott?

0 Karma

lycollicott
Motivator

Nothing beyond the workaround.

0 Karma

lycollicott
Motivator

AQR= attributeQueryRequest

I'm actually on a webex with Splunk Support on this very thing right now.

maciep
Champion

it might be worth opening a case with Splunk Support. Looks like someone else is seeing this recently as well

https://answers.splunk.com/answers/588332/what-is-aqr-and-why-is-it-throwing-warning-message-1.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...