Splunk Enterprise

Why does Splunk not allow me to create users after upgrade?

mariorodriguez
Engager

Good day friends...


I expose the following issue:

A little over a month ago we upgraded the splunk version from 7.0 to 8.1.7.2, I do not know if because of the upgrade splunk no longer let me create users marking the following error: "In handler 'users': Could not get info for role that does not exist: windows-admin".

I also removed the apps that splunk had and that are compatible, among them "Splunk App for Windows Infrastructure". I don't know if this or the above generated this problem.

Can you help me if anyone has had this happen and how did you solve it?

thanks

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@mariorodriguez - I think you need to remove all occurrences.

(As Splunk error message is saying "passwd file says the windows-admin role is attached to some user but Splunk cannot find that role.")

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@mariorodriguez - I think you have that the role name (windows-admin) is still present in passwd file while the role itself has been removed.

Please find the file $SPLUNK_HOME/etc/passwd, and you need to clean up the "windows-admin" word properly. Please make sure you do not mess with the format of the file. And after the change, restart Splunk. (taking a backup of the file is always a good idea.)

 

I hope this helps!!!

0 Karma

mariorodriguez
Engager

thanks @VatsalJagani but I have a doubt, when opening the password file, the word "windows-admin", do I have to delete it for each user or should it be in a specific line?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@mariorodriguez - I think you need to remove all occurrences.

(As Splunk error message is saying "passwd file says the windows-admin role is attached to some user but Splunk cannot find that role.")

0 Karma

mariorodriguez
Engager

@VatsalJaganiThank you very much, it is already solved as you indicated.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...