<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem logging into splunk in Security</title>
    <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84032#M14135</link>
    <description>&lt;P&gt;Are you using Splunk and or LDAP to authenticate?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2014 18:21:03 GMT</pubDate>
    <dc:creator>Voltaire</dc:creator>
    <dc:date>2014-07-23T18:21:03Z</dc:date>
    <item>
      <title>Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84028#M14131</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have been using the same credential to login to my Splunk, but all of a sudden it stops working this afternoon. The log shows the following error. I know my password is correct because it's my AD account and I use the same pwd to login to my computer. How can I troubleshoot this login problem?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;PRE&gt;
2013-04-03 14:52:55,190 ERROR   [515ca4b6f952fec88] account:216 - user=xxx action=login status=failure reason=user-initiated useragent="Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3)" clientip=xx.xx.x.xxx
&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Apr 2013 22:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84028#M14131</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-04-03T22:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84029#M14132</link>
      <description>&lt;P&gt;Hey lain179,&lt;BR /&gt;
I am not sure how splunk works with DA, but have you had a look at the passwd file that holds default user details in:&lt;BR /&gt;
$SPLUNKHOME/etc/passwd&lt;BR /&gt;
Might be somewhere to start.&lt;BR /&gt;
Regards Vince&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2013 22:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84029#M14132</guid>
      <dc:creator>vincesesto</dc:creator>
      <dc:date>2013-04-03T22:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84030#M14133</link>
      <description>&lt;P&gt;That only has a list of the accounts created in Splunk. Not AD accounts. Other people from same AD group don't have any problem logging in.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2013 23:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84030#M14133</guid>
      <dc:creator>lain179</dc:creator>
      <dc:date>2013-04-03T23:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84031#M14134</link>
      <description>&lt;P&gt;We have the same issue - did you find anything on this? thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 15:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84031#M14134</guid>
      <dc:creator>nurtdi</dc:creator>
      <dc:date>2014-07-23T15:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84032#M14135</link>
      <description>&lt;P&gt;Are you using Splunk and or LDAP to authenticate?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 18:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84032#M14135</guid>
      <dc:creator>Voltaire</dc:creator>
      <dc:date>2014-07-23T18:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84033#M14136</link>
      <description>&lt;P&gt;If it is Splunk, yu can change the password here "$SPLUNKHOME/etc/passwd" Restart splunk and login with the Splunk default password&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 18:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84033#M14136</guid>
      <dc:creator>Voltaire</dc:creator>
      <dc:date>2014-07-23T18:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84034#M14137</link>
      <description>&lt;P&gt;This is only affecting AD users&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 18:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84034#M14137</guid>
      <dc:creator>nurtdi</dc:creator>
      <dc:date>2014-07-23T18:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84035#M14138</link>
      <description>&lt;P&gt;Are you using LDAP to authenticate to AD with Splunk??&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 18:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84035#M14138</guid>
      <dc:creator>Voltaire</dc:creator>
      <dc:date>2014-07-23T18:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84036#M14139</link>
      <description>&lt;P&gt;Yes! I see the issue with AD users. &lt;BR /&gt;
the search-heads have same error as in original question. and it is not a single server that has an issue.&lt;BR /&gt;
This search 'index=_* "action=login status=failure" | stats count by user reason date_month date_mday date_wday date_hour host' sorts it out and I can see different users and different hosts with the error - all intermittent.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84036#M14139</guid>
      <dc:creator>nurtdi</dc:creator>
      <dc:date>2020-09-28T17:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem logging into splunk</title>
      <link>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84037#M14140</link>
      <description>&lt;P&gt;Did you configure LDAP roles in Splunk for authentications? If yes, did you use LDAP search method or another utility to verify the LDAP attributes in configuring the "LDAP connection settings" &lt;BR /&gt;
For example did you verify The Group base DN? Exaple &lt;BR /&gt;
"OU=Security Groups - AIS,DC=ad,DC=it,DC=yourdc,DC=ext&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 19:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Problem-logging-into-splunk/m-p/84037#M14140</guid>
      <dc:creator>Voltaire</dc:creator>
      <dc:date>2014-07-23T19:22:32Z</dc:date>
    </item>
  </channel>
</rss>

