Splunk Search

Inability to delete alerts/reports after LDAP update

Reece
Loves-to-Learn

Hello,
I recently updated a distributed environment with a bundle via the deployer to update the authentication.conf to have an updated LDAP strategy.  Since then there have been a number of issue with users not being able to delete their knowledge objects which prompted me to try as my Admin user. However this is the error I am receiving when trying to delete via the web ui:

09-24-2024 16:52:13.948 +0000 ERROR SavedSearchAdminHandler [2802356 TcpChannelThread] - This saved search failed to handle removal request due to Object id=<alert/report name> cannot be deleted in config=savedsearches.

I am using Splunk Enterprise version 9.3.0.

0 Karma

dural_yyz
Motivator

If you have a search head cluster on prem try electing a new captain to force push a new SHC bundle.

If that doesn't work then more information would be required about how user and roles are working and if you have any thing has changed there.  Is there anything via auth .conf doesn't show up anymore.

0 Karma

Reece
Loves-to-Learn

I have elected a new captain in my SH cluster a few times over the course of a couple days to see if there was some type of connection issue b/w specific SHs but still presenting same error. The only changes in auth.conf were the ldap servers, the hosts, the groupings and permissions are all identical. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...