Security

on a searchhead users with new roles can not see data from the indexer

imrago
Contributor

Hi,

I encountered a strange problem, starting from few days ago, newly created roles on the searchhead are unable to access indexes on the indexer only the local are visible. Roles created earlier are working as expected.
In the logs I could not find any hint on the source of the problem.

How could I find the source of this problem?

Tags (2)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

0 Karma

imrago
Contributor

Thank you for the clue, after the update to 4.2.4 the bundles on the indexer stopped being refreshed.

0 Karma

imrago
Contributor

I am not using mounted knowledge bundle, I assume that knowledge bundle is sent on every distributed search query.
Could it be that my knowledge bundle is to large? Are there limitations on that?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...