Splunk Search

clean up user account that errors from automatic lookup

jkeellogic
Explorer

My user account I created some automatic lookup, but now I can't delete them in the browser.

The problem was a fat finger as I did with a cut & paste in the box "named" which caused the problem.
I think a colon got inserted.

How can I delete them with a cli command for that user account?

Or how can I edit the "named" option when I created it in the first place?

I noticed you can edit what you put in.

Any ideas
jim

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi jkeellogic,

If you have CLI access to the server, fine. First check in the Splunk UI at URI http[s]:YourSplunkServer:[YourSplunkPort]/en-GB/manager/search/data/lookup-table-files and http[s]:YourSplunkServer:[YourSplunkPort]/en-GB/manager/search/data/transforms/lookups where you can find the files on your Splunk server. Then login and change directory to this folder and modify any props.conf and transforms.conf containing information related to this lookup.

There is also a REST API method to change the setting, but modifying the files is much easier.

And if I got your completely wrong and you want to remove the user account, simply edit $SPLUNK_HOME/etc/passwd and remove the user in this file and restart Splunk.
Hope that helps ...

cheers, MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...