Just updated my search heads to 4.3 and now I get following message when trying to create new roles in Splunk manager.
There was an error retrieving the configuration, can not process this page.
You do not have permission to access the configuration for this page.
No difference between LDAP user (with admin privilege) and local Admin user, both receive the same error.
my /opt/splunk/etc/apps/search/metadata/default.meta shows:
access = read : [ admin ], write : [ admin ]*
that should be okay.
Sometimes I see errors like this if Splunk was started/stopped by root, when it normally runs as a different user. Some of the files become owned by root and then odd things don't work. In Linux, there is a simple fix. Assuming that
you are signed in as a user with sudo privileges
sudo chown -R splunkit splunk
Of course, the problem could be something entirely different...