Thanks for your answer. I also saw the link you sent before, but in my case it is not a search head cluster environment. My problem is that when I connect from the windows client, it works normally, but when I connect from the macbook, a problem occurs. Of course kvstore is working normally.
... View more
Hi Splunker,
When creating or editing a new Correlation Search, the items of "Adaptive Response Actions" do not appear and the following error occurs. The peculiarity only occurs when connecting from a macbook, and works normally when connecting from Windows.
The current environment is Splunk 9.0.5 + ES 7.1.1, but this has occurred since ES 7.x, a year ago.
Thanks
... View more
Splunk's password policy does not lockout to the admin role by default.
To do this, add the following settings to the authorize.conf file.
$ SPLUNK_HOME / system / local / authorize.conf
[role_admin]
never_lockout = disabled
... View more