Security

db_connect v3 cannot delete inputs when using SAML

duneclarke2
Explorer

WARN UserManagerPro - AQR not supported and user=username@domain.com information not found in cache or 404 User not found

C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\metadata\local.meta
 
When trying to delete inputs created in dbconnect, splunk was not able to authenticate the user via our IDP. To workaround this, edit local.meta, find the input to be deleted and change the owner =  username@domain.com  to owner = nobody. 
 
Restart the splunkd service. 

 

 

 

Labels (1)
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...