Splunk Search

AuthorizationManager related error messages.

dm1
Contributor

 10-27-2025 03:21:21.006 WARN  AuthorizationManager [28813 MainThread] - Capability 'use_file_operator' is not recognized by Splunk. Ignoring...
10-27-2025 03:21:21.054 ERROR AuthenticationManager [28813 MainThread] - preserveStateDuringReload: Method not implemented
10-27-2025 03:21:21.134 ERROR SystemInfo [25968 RunDispatch] - Failed to read memory limit at location="V1:/sys/fs/cgroup/cpu,cpuacct:/:/sys/fs/cgroup/memory:/:"

Could anyone please help fixing these error messages ?

Tags (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @dm1 

The capability 'use_file_operator' is part of a deprecated feature - whilst it is still listed in the docs (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.0/manage-splunk...) it has no effect and can be ignored. This is a benign error and not causing any issues.

You can find out where this is being applied by running a btool and looking for the 'use_file_operator' 

$SPLUNK_HOME/bin/splunk btool authorize list --debug

 

Regarding the memory limit error - this could be a number of things - are you running inside a container? Is selinux enabled? Are you using the out of the box systemd configuration? Check out https://help.splunk.com/en/splunk-enterprise/administer/troubleshoot/10.0/system-administration-prob... for more info on configuring systemd and setting the memory limit within it which might help.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PrewinThomas
Motivator

@dm1 

Capability 'use_file_operator' is not recognized by Splunk. Ignoring...
Do you have any reference of use_file_operator in your authorize.conf? Any upgrade happened? You need to remove that entry from your authorize.conf as its not supported in your current splunk version.

preserveStateDuringReload: Method not implemented - I think you can ignore this for now, its just a placeholder warning, might be for future use.


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...