Splunk Search

Not able to access splunk

gajananh999
Contributor

Dear All,

We have splunk search head with 100's of user in it. But suddenly this morning what happened i dont know but none of user is not able to login. I can only login with Splunk admin account may i know what is the issue for this?

Thanks
Gajanan

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

What happens when you log in as local admin user and go to Settings -> Authentication -> Authentication Method -> Configure ... LDAP ... groups -> Your LDAP Strategy -> Map Groups?

My working hypothesis is that your Splunk instance cannot connect with your LDAP for some reason.

0 Karma

jimodonald
Contributor

Check to see if the service account is locked out on the LDAP server.

gajananh999
Contributor

No one able to login. its Windows machine with splunk 6.0.2

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Sounds like that's your problem. Check the user exists obviously, and that Splunk can connect to the server.

What version are you using, and on what OS?

0 Karma

gajananh999
Contributor

Martin.. 07-15-2014 06:23:33.216 -0400 ERROR UserManagerPro - Failed to get LDAP user="m8000" from any configured servers

0 Karma

gajananh999
Contributor

Dear Martin its working fine its giving me a result.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Oops, try *LDAP*. Alternatively, take the time of a failed attempt and look at everything that happened around that time.

0 Karma

gajananh999
Contributor

index=_internal LDAP* its not giving any result..

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Check if that's working as it should.

For example, search the _internal index for LDAP*.

0 Karma

gajananh999
Contributor

Yes we use LDAP

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

So the licensing page tells you your license is valid? Great.

Do you use external authentication, such as LDAP/AD/etc.?

0 Karma

gajananh999
Contributor

Thanks for your reply.There is No licensing alerts.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Check your license messages. Either click Messages if nobody deleted them yet, or go to Settings -> Licensing and see what that says.

0 Karma
Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...