Security

on a searchhead users with new roles can not see data from the indexer

imrago
Contributor

Hi,

I encountered a strange problem, starting from few days ago, newly created roles on the searchhead are unable to access indexes on the indexer only the local are visible. Roles created earlier are working as expected.
In the logs I could not find any hint on the source of the problem.

How could I find the source of this problem?

Tags (2)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

0 Karma

imrago
Contributor

Thank you for the clue, after the update to 4.2.4 the bundles on the indexer stopped being refreshed.

0 Karma

imrago
Contributor

I am not using mounted knowledge bundle, I assume that knowledge bundle is sent on every distributed search query.
Could it be that my knowledge bundle is to large? Are there limitations on that?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...