Splunk integration (on-prem) - unable to save configuration, Delete User failed error

Problem

When configuring the Splunk Actionable IT Alerts integration, we are unable to save the configuration. We get the following error:

 

mceclip0.png

Error: Delete user failed. cannot find the credential information with id : credential:xmatters_password

 

Environment

Splunk on-prem version 8.2 and above

 

Resolution 

Check if the passwords.conf file exists and contains a credential pair for the xmatters account and its corresponding password. This may be encrypted. If missing, it has been found that you can create a password file with the same file permissions as the other conf files and supply the plaintext password so that it is formatted as the following.

[credential::xmatters_password:]
password = <plain_text_password>

The location of this file is in the Splunk application folder in the /apps/xmatters_alert_action/local folder.

An example on *nix systems:
/opt/splunk/etc/apps/xmatters_alert_action/local/passwords.conf

 

Resources

Reference for the passwords.conf file can be found here. https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/Passwords

 

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.