I am not able to log into the indexer with my auditor's account. When I log into with the admin account my profile is not visible. When I try to add my auditor's account as a new user it errors because the profile already exists. How can I remove the corrupted profile from the DB? Can you provide an SQL command? Thanks.
Hi,
You can also directly delete your profile directory of particular user under index server :
rm -r /opt/splunk/etc/users/username/
Regards!
Vinay
Hi @cyberspecialist,
You can use the ./splunk remove user username
command from the cli to delete a user.
This is will not delete the users artifacts. To do so you'll also have to get rid of the $SPLUNK_HOME/etc/user/username
folder.
Let me know if that helps.
Cheers,
David