Getting Data In

After upgrade to 6.5.0, why is my indexer reporting "ERROR UserManagerPro - Could not get info for non-existent user"?

ateterine
Path Finder

Hi Splunkers,

Haven't seen this message prior to 6.5 update, but now splunkd.log is full of it.

Any idea why it might be happening?

11-17-2016 14:52:08.837 -0800 WARN  IniFile - C:\Program Files\Splunk\var\run\searchpeers\bpsplunk-mstr-1479423126\apps\splunk_monitoring_console\metadata\local.meta, line 13: Cannot parse into key-value pair:       
11-17-2016 14:52:08.841 -0800 WARN  IniFile - C:\Program Files\Splunk\var\run\searchpeers\bpsplunk-mstr-1479423126\apps\learned\metadata\local.meta, line 17: Cannot parse into key-value pair:         
11-17-2016 14:52:19.555 -0800 ERROR UserManagerPro - Could not get info for non-existent user="username"
1
Tags (3)
0 Karma

swaro_ck
Path Finder

Hi, in the meantime I got an answer from Splunk Support, they will fix it in 6.5.3

Murali2888
Communicator

Hi swaro_ck,

Did we happen to get details on what the issue is?

0 Karma

swaro_ck
Path Finder

They just told me that the problem was fixed in 6.5.3 and after the update the message was gone. I got no details what exactly the problem was.

0 Karma

gjanders
SplunkTrust
SplunkTrust

I am getting

ERROR UserManagerPro - Failed to get LDAP user="XXX" from any configured servers
ERROR AuthenticationManagerLDAP - user="XXX" has matching LDAP groups with strategy="ldap"

but none are mapped to Splunk roles

After the 6.5 upgrade, is that similar or different to what you are seeing ?

teunlaan
Contributor

Have the same problem (6.5.1 and 6.5.2)
I noticed it only happens when we are running Real-time searches

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...