Security

on a searchhead users with new roles can not see data from the indexer

imrago
Contributor

Hi,

I encountered a strange problem, starting from few days ago, newly created roles on the searchhead are unable to access indexes on the indexer only the local are visible. Roles created earlier are working as expected.
In the logs I could not find any hint on the source of the problem.

How could I find the source of this problem?

Tags (2)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

What method are you using to distribute the knowledge bundle to your indexer ?
For example, if you are using mounted knowledge bundles you will need to copy the etc/system/local/authorize.conf file to your knowledge bundle mount for your indexer to pick up.

0 Karma

imrago
Contributor

Thank you for the clue, after the update to 4.2.4 the bundles on the indexer stopped being refreshed.

0 Karma

imrago
Contributor

I am not using mounted knowledge bundle, I assume that knowledge bundle is sent on every distributed search query.
Could it be that my knowledge bundle is to large? Are there limitations on that?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...