<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic API Token authentication in Security</title>
    <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515614#M11728</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;am trying to access :&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;curl -k &lt;A href="https://localhost:8089/services/auth/login" target="test_blank" rel="nofollow noopener noreferrer"&gt;https://localhost:8089/services/auth/login -d username=admin -d password=foobar&lt;/A&gt;&lt;/PRE&gt;&lt;P&gt;&lt;A href="https://localhost:8089/services/auth/login" target="test_blank" rel="nofollow noopener noreferrer"&gt;https://localhost:8089/services/auth/login&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Getting error , could you please tell me which credentials need to enter&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Sun, 23 Aug 2020 06:02:34 GMT</pubDate>
    <dc:creator>Rdoggala</dc:creator>
    <dc:date>2020-08-23T06:02:34Z</dc:date>
    <item>
      <title>API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515614#M11728</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;am trying to access :&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;curl -k &lt;A href="https://localhost:8089/services/auth/login" target="test_blank" rel="nofollow noopener noreferrer"&gt;https://localhost:8089/services/auth/login -d username=admin -d password=foobar&lt;/A&gt;&lt;/PRE&gt;&lt;P&gt;&lt;A href="https://localhost:8089/services/auth/login" target="test_blank" rel="nofollow noopener noreferrer"&gt;https://localhost:8089/services/auth/login&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Getting error , could you please tell me which credentials need to enter&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 23 Aug 2020 06:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515614#M11728</guid>
      <dc:creator>Rdoggala</dc:creator>
      <dc:date>2020-08-23T06:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515620#M11729</link>
      <description>&lt;PRE&gt;curl -k https://localhost:8089/services/auth/login --data-urlencode username=admin --data-urlencode password=pass&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/RESTUM/RESTusing#Authentication" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/RESTUM/RESTusing#Authentication&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 06:40:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515620#M11729</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-23T06:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515629#M11730</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;use curl -ku USER:PASSWORD &lt;A href="https://..." target="_blank" rel="noopener"&gt;https://...&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;and good habit is first read user:password to env variable like&lt;/P&gt;&lt;P&gt;read UP&lt;/P&gt;&lt;P&gt;and then use it on command like curl -ku $UP .....&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 10:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515629#M11730</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-23T10:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515633#M11731</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rdoggala_0-1598183417606.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10451iA504AEE7806CBB28/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Rdoggala_0-1598183417606.png" alt="Rdoggala_0-1598183417606.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Getting attached error, do you any idea&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 11:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515633#M11731</guid>
      <dc:creator>Rdoggala</dc:creator>
      <dc:date>2020-08-23T11:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515634#M11732</link>
      <description>&lt;P&gt;If I saw correct you have “search index*_internal” when it should be “search index=_internal”&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 12:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515634#M11732</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-23T12:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515637#M11733</link>
      <description>&lt;P&gt;sorry to asking this many questions, am very new to splunk&lt;/P&gt;&lt;P&gt;getting same error again, but end of the screen below error also coming&lt;/P&gt;&lt;P&gt;ConnectionRefusedError: [WinError 10061] No connection could be made because the target machine actively refused it&lt;/P&gt;&lt;P&gt;note: i have not installed splunk in my machine, please suggest me what to do&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your help&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 13:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515637#M11733</guid>
      <dc:creator>Rdoggala</dc:creator>
      <dc:date>2020-08-23T13:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515638#M11734</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have tried below&amp;nbsp;on my local machine and it's working fine.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;curl -k &lt;A href="https://localhost:8089/services/auth/login" target="test_blank" rel="nofollow noopener noreferrer noopener noreferrer"&gt;https://localhost:8089/services/auth/login -d username=admin -d password=foobar&lt;/A&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you mentioned you have not installed Splunk on local machine, then how you could connect localhost:8089, replace localhost with IP which you are trying to connect.&lt;/P&gt;&lt;P&gt;and make sure, you have connectivity to the IP from the machine you are trying from over port 8089.&amp;nbsp;&lt;/P&gt;&lt;P&gt;you could test connectivity by using telnet&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet targetIP 8089&lt;/LI-CODE&gt;&lt;P&gt;if the results says connected, that means you have connectivity.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 13:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515638#M11734</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-23T13:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515641#M11735</link>
      <description>&lt;P&gt;Thank you very much for prompt reply.&lt;/P&gt;&lt;P&gt;1. is splunk works on 8089 host only?&lt;/P&gt;&lt;P&gt;2.due to admin access , i have not installed splunk in my machine. is there any specifications (host , port and others) to mention if am&amp;nbsp; installing?&lt;/P&gt;&lt;P&gt;3.i wanted to download dashboard graphs from spunk using python script, is this possible? if yes give some ideas?&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 13:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515641#M11735</guid>
      <dc:creator>Rdoggala</dc:creator>
      <dc:date>2020-08-23T13:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515644#M11736</link>
      <description>&lt;P&gt;I think you need to understand below first:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;what are common ports used in Splunk and their purpose&lt;/LI&gt;&lt;LI&gt;Little bit network concepts.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Splunkweb is web page where you can interact with Splunk and it runs on 8000 port by default.&lt;/P&gt;&lt;P&gt;if Splunk is running on your local machine, you could connect Splunk web using url &lt;A href="http://localhost:8000" target="_blank"&gt;http://localhost:8000&lt;/A&gt;&amp;nbsp;or &lt;A href="http://127.0.0.1:8000" target="_blank"&gt;http://127.0.0.1:8000&lt;/A&gt;&amp;nbsp;and you could connect Splunk web using url &lt;A href="https://localhost:8000" target="_blank"&gt;https://localhost:8000&lt;/A&gt;&amp;nbsp;or &lt;A href="https://127.0.0.1" target="_blank"&gt;https://127.0.0.1&lt;/A&gt;&amp;nbsp;if ssl is enabled in Splunk web.conf.&lt;/P&gt;&lt;P&gt;Splunk has management port i.e 8089 and this is mainly used for managing Splunk&amp;nbsp; using rest API calls.&lt;/P&gt;&lt;P&gt;to access Splunk from other machine (not locally), to connect splunkweb the url should be &lt;A href="http://ip:8000" target="_blank"&gt;http://ip:8000&lt;/A&gt;&amp;nbsp;or &lt;A href="https://ip:8000" target="_blank"&gt;https://ip:8000&lt;/A&gt;&amp;nbsp;if ssl is enabled and your Splunk is not setup with custom port.&lt;/P&gt;&lt;P&gt;since you are talking about connecting to Splunk using rest API , the default management port is 8089.&lt;/P&gt;&lt;P&gt;first , check the connectivity from the box you are trying to where Splunk is installed over the port 8089 using telnet as I mentioned before.&lt;/P&gt;&lt;P&gt;coming to your second question that you can download dashboard from Splunk, I don' t think you can download dashboard , but I am sure you can run searches and fetch results.&lt;/P&gt;&lt;P&gt;follow below link.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Search/ExportdatausingRESTAPI" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Search/ExportdatausingRESTAPI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 14:05:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515644#M11736</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-23T14:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515647#M11737</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp; really informative details&amp;nbsp;&lt;/P&gt;&lt;P&gt;i dont have splunk on my machine , i have registered splunk cloud and using since 2days.&lt;/P&gt;&lt;P&gt;1.tested three hosts 8000,8089 and 8080, all are connection failed&lt;/P&gt;&lt;P&gt;2.i don't&amp;nbsp; have any data in splunk cloud , could you please tell me how i can get&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rdoggala_0-1598192651566.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10452i7989F3F6414B5017/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Rdoggala_0-1598192651566.png" alt="Rdoggala_0-1598192651566.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3. as you said we can export result from splunk dashboard, may i know in which format we get the result.&lt;/P&gt;&lt;P&gt;4.can we export dashboard&amp;nbsp; to the PPT?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 14:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515647#M11737</guid>
      <dc:creator>Rdoggala</dc:creator>
      <dc:date>2020-08-23T14:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: API Token authentication</title>
      <link>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515649#M11738</link>
      <description>&lt;P&gt;the page what you have shared is from splunkweb only.&lt;/P&gt;&lt;P&gt;if you are using corporate laptop, there could be connectivity issues since you are trying to connect the host and port unknown.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Aug 2020 14:30:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/API-Token-authentication/m-p/515649#M11738</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-23T14:30:06Z</dc:date>
    </item>
  </channel>
</rss>

