Posting here since this is the first result on search engines. In my case I was adding a new user and probably I messed up something with the roles/capabilities.
What I was trying to achive is create an user with reduced capabilities, what i got is running Splunk instance (splunkd) but with admin user unable to view/change/modify anything or do any searches!
Restarting splunk did not help, neither trying to modify/deleting accounts with CLI, as far as I can tell. Looking for the log as OP did raise my attention on ServerZoneInfo, but i really couldn't understand its meaning.
What I did is modify the file in $SPLUNK_HOME/etc/system/default/authorize.conf and enabling capabilities for specified roles. Playing a little with this files gives me back access and admin account worked correctly.
Hope this helps anyone
... View more