Splunk Search

AuthorizationManager related error messages.

dm1
Contributor

 10-27-2025 03:21:21.006 WARN  AuthorizationManager [28813 MainThread] - Capability 'use_file_operator' is not recognized by Splunk. Ignoring...
10-27-2025 03:21:21.054 ERROR AuthenticationManager [28813 MainThread] - preserveStateDuringReload: Method not implemented
10-27-2025 03:21:21.134 ERROR SystemInfo [25968 RunDispatch] - Failed to read memory limit at location="V1:/sys/fs/cgroup/cpu,cpuacct:/:/sys/fs/cgroup/memory:/:"

Could anyone please help fixing these error messages ?

Tags (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @dm1 

The capability 'use_file_operator' is part of a deprecated feature - whilst it is still listed in the docs (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.0/manage-splunk...) it has no effect and can be ignored. This is a benign error and not causing any issues.

You can find out where this is being applied by running a btool and looking for the 'use_file_operator' 

$SPLUNK_HOME/bin/splunk btool authorize list --debug

 

Regarding the memory limit error - this could be a number of things - are you running inside a container? Is selinux enabled? Are you using the out of the box systemd configuration? Check out https://help.splunk.com/en/splunk-enterprise/administer/troubleshoot/10.0/system-administration-prob... for more info on configuring systemd and setting the memory limit within it which might help.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PrewinThomas
Motivator

@dm1 

Capability 'use_file_operator' is not recognized by Splunk. Ignoring...
Do you have any reference of use_file_operator in your authorize.conf? Any upgrade happened? You need to remove that entry from your authorize.conf as its not supported in your current splunk version.

preserveStateDuringReload: Method not implemented - I think you can ignore this for now, its just a placeholder warning, might be for future use.


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...