Security

My profile is corrupted

cyberspecialist
New Member

I am not able to log into the indexer with my auditor's account. When I log into with the admin account my profile is not visible. When I try to add my auditor's account as a new user it errors because the profile already exists. How can I remove the corrupted profile from the DB? Can you provide an SQL command? Thanks.

Tags (2)
0 Karma

vinaybandaru
Path Finder

Hi,

You can also directly delete your profile directory of particular user under index server :
rm -r /opt/splunk/etc/users/username/

Regards!
Vinay

0 Karma

DavidHourani
Super Champion

Hi @cyberspecialist,

You can use the ./splunk remove user username command from the cli to delete a user.

This is will not delete the users artifacts. To do so you'll also have to get rid of the $SPLUNK_HOME/etc/user/username folder.

Let me know if that helps.

Cheers,
David

0 Karma