Splunk Enterprise Security

My Key Security Indicators aren't working after removing the default "admin" account (display "Unable to load results")

LukeMurphey
Champion

I recently removed the default "admin" account and am now finding that the Key Indicators no longer work. Are these related? Does ES require the admin user to exist?

0 Karma
1 Solution

LukeMurphey
Champion

ES does require that the "admin" account exist. By default, saved searches use "dispatchAs" setting of "owner". The owner of the searches is set to "admin" via default.meta.

Thus, removing the admin user will cause searches to fail. If the admin user to removed, then the following error will be observed when searches are executed that attempt to run under the admin user:

'DispatchManager': The user 'admin' does not have sufficient search privileges.

To fix this issue, restore the admin user. The searches should begin working immediately (no restart required).

View solution in original post

0 Karma

LukeMurphey
Champion

ES does require that the "admin" account exist. By default, saved searches use "dispatchAs" setting of "owner". The owner of the searches is set to "admin" via default.meta.

Thus, removing the admin user will cause searches to fail. If the admin user to removed, then the following error will be observed when searches are executed that attempt to run under the admin user:

'DispatchManager': The user 'admin' does not have sufficient search privileges.

To fix this issue, restore the admin user. The searches should begin working immediately (no restart required).

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...