Security

How to permanently remove accounts remaining after removing passwd file?

a212830
Champion

Hi,

I am in the process of rebuilding my dev environment, and am taking over an existing search-head that wasn't being used. I upgraded to 6.1.3, and then renamed the passwd file, so that all the old accounts were removed. However, there are still a number of ldap-based accounts appearing, and if I try to delete them via the gui, a message appears saying that "user account does not exist". Is there another place where they need to be removed from? I looked in the passwd file, and they are not present.

Tags (2)

hsesterhenn_spl
Splunk Employee
Splunk Employee

As far as I understand the docs directories in etc/users are automatically created as long as you can successfully log in via LDAP.

HTH,

Holger

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...