Splunk Search

Not able to access splunk

gajananh999
Contributor

Dear All,

We have splunk search head with 100's of user in it. But suddenly this morning what happened i dont know but none of user is not able to login. I can only login with Splunk admin account may i know what is the issue for this?

Thanks
Gajanan

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

What happens when you log in as local admin user and go to Settings -> Authentication -> Authentication Method -> Configure ... LDAP ... groups -> Your LDAP Strategy -> Map Groups?

My working hypothesis is that your Splunk instance cannot connect with your LDAP for some reason.

0 Karma

jimodonald
Contributor

Check to see if the service account is locked out on the LDAP server.

gajananh999
Contributor

No one able to login. its Windows machine with splunk 6.0.2

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Sounds like that's your problem. Check the user exists obviously, and that Splunk can connect to the server.

What version are you using, and on what OS?

0 Karma

gajananh999
Contributor

Martin.. 07-15-2014 06:23:33.216 -0400 ERROR UserManagerPro - Failed to get LDAP user="m8000" from any configured servers

0 Karma

gajananh999
Contributor

Dear Martin its working fine its giving me a result.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Oops, try *LDAP*. Alternatively, take the time of a failed attempt and look at everything that happened around that time.

0 Karma

gajananh999
Contributor

index=_internal LDAP* its not giving any result..

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Check if that's working as it should.

For example, search the _internal index for LDAP*.

0 Karma

gajananh999
Contributor

Yes we use LDAP

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

So the licensing page tells you your license is valid? Great.

Do you use external authentication, such as LDAP/AD/etc.?

0 Karma

gajananh999
Contributor

Thanks for your reply.There is No licensing alerts.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Check your license messages. Either click Messages if nobody deleted them yet, or go to Settings -> Licensing and see what that says.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...