Good day friends...
I expose the following issue:
A little over a month ago we upgraded the splunk version from 7.0 to 8.1.7.2, I do not know if because of the upgrade splunk no longer let me create users marking the following error: "In handler 'users': Could not get info for role that does not exist: windows-admin".
I also removed the apps that splunk had and that are compatible, among them "Splunk App for Windows Infrastructure". I don't know if this or the above generated this problem.
Can you help me if anyone has had this happen and how did you solve it?
thanks
@mariorodriguez - I think you need to remove all occurrences.
(As Splunk error message is saying "passwd file says the windows-admin role is attached to some user but Splunk cannot find that role.")
@mariorodriguez - I think you have that the role name (windows-admin) is still present in passwd file while the role itself has been removed.
Please find the file $SPLUNK_HOME/etc/passwd, and you need to clean up the "windows-admin" word properly. Please make sure you do not mess with the format of the file. And after the change, restart Splunk. (taking a backup of the file is always a good idea.)
I hope this helps!!!
thanks @VatsalJagani but I have a doubt, when opening the password file, the word "windows-admin", do I have to delete it for each user or should it be in a specific line?
@mariorodriguez - I think you need to remove all occurrences.
(As Splunk error message is saying "passwd file says the windows-admin role is attached to some user but Splunk cannot find that role.")
@VatsalJaganiThank you very much, it is already solved as you indicated.