Security

How do you resolve splunk.log error messages after switching authentication from LDAP to SAML?

DennisFFM
Explorer

Hey guys,

After changing our authentication system from LDAP to SAML we get a lot of messages like this in splunkd.log:

11-07-2017 18:35:00.904 +0100 WARN UserManagerPro - AQR not supported and user=system information not found in cache

All I could find out by myself is, that "AQR" is likely to mean "Assessor qualification & requirements" and it has something to do with SAML.

Can anybody help here?

Greetings
Dennis

lycollicott
Motivator

Dennis, we've been trying to figure this out for a while now and I've had a few Webex on it. The analyst and I think it's probably a bug and probably harmless, but we might also have a temporary workaround.

We created a local splunk user called system and gave it a weak role ....those messages ended immediately. I'll keep you updated.

DennisWoerner
Explorer

Hi @lycollicott,

Thank you for your answer!
That sounds like a good workaround.

I didn't investigate this error any further, as it isn't really a 'problem'.

Do you have already an update on this?

0 Karma

lycollicott
Motivator

There is nothing new to report on this, but the workaround is still in place.

0 Karma

scannon4
Communicator

That is what we did as well as a workaround, lycollicott

0 Karma

woodcock
Esteemed Legend

So did you ever get an answer, @lycollicott?

0 Karma

lycollicott
Motivator

Nothing beyond the workaround.

0 Karma

lycollicott
Motivator

AQR= attributeQueryRequest

I'm actually on a webex with Splunk Support on this very thing right now.

maciep
Champion

it might be worth opening a case with Splunk Support. Looks like someone else is seeing this recently as well

https://answers.splunk.com/answers/588332/what-is-aqr-and-why-is-it-throwing-warning-message-1.html

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...