Splunk Dev

Restore Admin Roles in Splunk After Accidental Deletion

sanjai
Path Finder

Hi Splunker,

I am currently working with REST API calls for user management in Splunk. While attempting to add additional roles to the default admin account, I accidentally removed the admin role from this account. Unfortunately, I do not have any other user accounts with admin privileges.

At present, I only have a single user account with the "User" role and cannot create a new user with "Admin" privileges.

Could you please advise on how to restore the deleted roles to the existing user account or suggest any alternative solutions?

 

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
And if you haven’t backups (you really should), just add role admin to your admin user into authorize.conf file with any text editor. See authorize.conf specs how it should do.

View solution in original post

sanjai
Path Finder

Thanks @richgalloway  and @isoutamo  for your time , it worked 🙂🙌

richgalloway
SplunkTrust
SplunkTrust

Restore the $SPLUNK_HOME/etc/system/local/authorize.conf file from your most recent backup and restart Splunk.

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
And if you haven’t backups (you really should), just add role admin to your admin user into authorize.conf file with any text editor. See authorize.conf specs how it should do.
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...