Splunk Search

clean up user account that errors from automatic lookup

jkeellogic
Explorer

My user account I created some automatic lookup, but now I can't delete them in the browser.

The problem was a fat finger as I did with a cut & paste in the box "named" which caused the problem.
I think a colon got inserted.

How can I delete them with a cli command for that user account?

Or how can I edit the "named" option when I created it in the first place?

I noticed you can edit what you put in.

Any ideas
jim

0 Karma

MuS
Legend

Hi jkeellogic,

If you have CLI access to the server, fine. First check in the Splunk UI at URI http[s]:YourSplunkServer:[YourSplunkPort]/en-GB/manager/search/data/lookup-table-files and http[s]:YourSplunkServer:[YourSplunkPort]/en-GB/manager/search/data/transforms/lookups where you can find the files on your Splunk server. Then login and change directory to this folder and modify any props.conf and transforms.conf containing information related to this lookup.

There is also a REST API method to change the setting, but modifying the files is much easier.

And if I got your completely wrong and you want to remove the user account, simply edit $SPLUNK_HOME/etc/passwd and remove the user in this file and restart Splunk.
Hope that helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...