Dear All,
We have splunk search head with 100's of user in it. But suddenly this morning what happened i dont know but none of user is not able to login. I can only login with Splunk admin account may i know what is the issue for this?
Thanks
Gajanan
What happens when you log in as local admin user and go to Settings -> Authentication -> Authentication Method -> Configure ... LDAP ... groups -> Your LDAP Strategy -> Map Groups?
My working hypothesis is that your Splunk instance cannot connect with your LDAP for some reason.
Check to see if the service account is locked out on the LDAP server.
No one able to login. its Windows machine with splunk 6.0.2
Sounds like that's your problem. Check the user exists obviously, and that Splunk can connect to the server.
What version are you using, and on what OS?
Martin.. 07-15-2014 06:23:33.216 -0400 ERROR UserManagerPro - Failed to get LDAP user="m8000" from any configured servers
Dear Martin its working fine its giving me a result.
Oops, try *LDAP*
. Alternatively, take the time of a failed attempt and look at everything that happened around that time.
index=_internal LDAP* its not giving any result..
Check if that's working as it should.
For example, search the _internal
index for LDAP*
.
Yes we use LDAP
So the licensing page tells you your license is valid? Great.
Do you use external authentication, such as LDAP/AD/etc.?
Thanks for your reply.There is No licensing alerts.
Check your license messages. Either click Messages if nobody deleted them yet, or go to Settings -> Licensing and see what that says.