Splunk Enterprise Security

migration

SN1
Path Finder

Recently I migrated ES from one SH to another non cluther SH . this error was popping in the panel of ES app

Error in 'DispatchManager': The user 'admin' does not have sufficient search privileges.

So to resolve this i searched about this error and there was a solution to remove owner=admin from default.meta file . It worked for some panels but some panels still show this error.

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@SN1 

ES does require that the "admin" account exist. By default, saved searches use "dispatchAs" setting of "owner". The owner of the searches is set to "admin" via default.meta.

Thus, removing the admin user will cause searches to fail. If the admin user to removed, then the following error will be observed when searches are executed that attempt to run under the admin user:

'DispatchManager': The user 'admin' does not have sufficient search privileges.

To fix this issue, restore the admin user. The searches should begin working immediately (no restart required).

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

SN1
Path Finder

Could you please tell me how to restore admin?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...