Security

on a searchhead users with new roles can not see data from the indexer

imrago
Contributor

Hi,

I encountered a strange problem, starting from few days ago, newly created roles on the searchhead are unable to access indexes on the indexer only the local are visible. Roles created earlier are working as expected.
In the logs I could not find any hint on the source of the problem.

How could I find the source of this problem?

Tags (2)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

0 Karma

imrago
Contributor

Thank you for the clue, after the update to 4.2.4 the bundles on the indexer stopped being refreshed.

0 Karma

imrago
Contributor

I am not using mounted knowledge bundle, I assume that knowledge bundle is sent on every distributed search query.
Could it be that my knowledge bundle is to large? Are there limitations on that?

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...