Manually adding doesn't work anyway... 😞
But in splunkd.log I can see this:
05-06-2014 16:11:49.650 +0200 ERROR AdminHandler:Exec - passAuth user does not exist: splunk-system-user
05-06-2014 16:11:49.669 +0200 ERROR AdminManager - Failed to create scripted input!
For adding probe I use credentials of the probe (admin privilege, not operator). What user doesn't exist?
Thanks again in advance!
I use free trial splunk! Could it be problem? It's just for testing now, which SIEM console we should choose. For LOG server is Splunk the best solution so I hope for SIEM would be too 😉
R.
... View more