After changing our authentication system from LDAP to SAML we get a lot of messages like this in splunkd.log:
11-07-2017 18:35:00.904 +0100 WARN UserManagerPro - AQR not supported and user=system information not found in cache
All I could find out by myself is, that "AQR" is likely to mean "Assessor qualification & requirements" and it has something to do with SAML.
Can anybody help here?
Dennis, we've been trying to figure this out for a while now and I've had a few Webex on it. The analyst and I think it's probably a bug and probably harmless, but we might also have a temporary workaround.
We created a local splunk user called system and gave it a weak role ....those messages ended immediately. I'll keep you updated.
Thank you for your answer!
That sounds like a good workaround.
I didn't investigate this error any further, as it isn't really a 'problem'.
Do you have already an update on this?
it might be worth opening a case with Splunk Support. Looks like someone else is seeing this recently as well