Security

db_connect v3 cannot delete inputs when using SAML

duneclarke2
Explorer

WARN UserManagerPro - AQR not supported and user=username@domain.com information not found in cache or 404 User not found

C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\metadata\local.meta
 
When trying to delete inputs created in dbconnect, splunk was not able to authenticate the user via our IDP. To workaround this, edit local.meta, find the input to be deleted and change the owner =  username@domain.com  to owner = nobody. 
 
Restart the splunkd service. 

 

 

 

Labels (1)
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...