<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 401 Unauthorized! Why? in Security</title>
    <link>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12839#M244</link>
    <description>&lt;P&gt;The version i tested is splunk 4.1, and the root_endpoint is set to /splunk.&lt;/P&gt;

&lt;P&gt;I cloned an application mysearch from search, and set session timeout to 24 hours. Then i created two dashboards dashboard1 (default view of mysearch) and dashboard2.&lt;/P&gt;

&lt;P&gt;Because there is no login page in free license, so first time i view ｈｔｔｐ://myip/splunk/en-US/app/mysearch, the browser will be redirected to ｈｔｔｐ://myip/splunk/en-US/app/search/dashboard. Next, i relocated to ｈｔｔｐ://myip/splunk/en-US/app/mysearch, the browser was redirected to the default view ｈｔｔｐ://myip/splunk/en-US/app/mysearch/dashboard1. Next, when i drilled down from dashboard1 or changed menu to dashboard2 or other operations, i aperiodically got "401 Unauthorized" errors and was kicked back to ｈｔｔｐ://myip/splunk/en-US/app/search/dashboard many times.&lt;/P&gt;

&lt;P&gt;From firebug, i got the following 2 kinds of responses for "401 unauthorized":&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;1) Splunk cannot authenticate the request. CSRF validation failed.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;2) No permission -- see authorization schemes&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;when i requested the following addresses&lt;/P&gt;

&lt;P&gt;a)
ｈｔｔｐ://myip/splunk/en-US/app/mysearch/flashtimeline/_current?FlashTimeline_0_5_0.minimized=false&lt;/P&gt;

&lt;P&gt;b)
ｈｔｔｐ://myip/splunk/en-US/api/search/jobs?auto_cancel=90&amp;amp;earliest_time=-4h%40h&amp;amp;latest_time=now&amp;amp;namespace=mysearch&amp;amp;search=search%20eventtype%3D%22*-TEST-*%22%20%7C%20timechart%20count%20as%20Total&amp;amp;status_buckets=0&amp;amp;ui_dispatch_app=mysearch&amp;amp;ui_dispatch_view=dashboard2&lt;/P&gt;

&lt;P&gt;c)
ｈｔｔｐ://myip/splunk/en-US/api/messages/index.&lt;/P&gt;

&lt;P&gt;d)
.......&lt;/P&gt;

&lt;P&gt;I think we should login as user "admin" in default and have all permissions in free splunk. And i got nothing about "CSRF validation failed" and "authorization schemes" in this forum and from google. Can anyone give me some suggestions about this?&lt;/P&gt;

&lt;P&gt;Thanks &amp;amp; Best Regards.&lt;/P&gt;

&lt;P&gt;Dianbo&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2010 08:44:27 GMT</pubDate>
    <dc:creator>dianbo_1</dc:creator>
    <dc:date>2010-05-04T08:44:27Z</dc:date>
    <item>
      <title>401 Unauthorized! Why?</title>
      <link>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12839#M244</link>
      <description>&lt;P&gt;The version i tested is splunk 4.1, and the root_endpoint is set to /splunk.&lt;/P&gt;

&lt;P&gt;I cloned an application mysearch from search, and set session timeout to 24 hours. Then i created two dashboards dashboard1 (default view of mysearch) and dashboard2.&lt;/P&gt;

&lt;P&gt;Because there is no login page in free license, so first time i view ｈｔｔｐ://myip/splunk/en-US/app/mysearch, the browser will be redirected to ｈｔｔｐ://myip/splunk/en-US/app/search/dashboard. Next, i relocated to ｈｔｔｐ://myip/splunk/en-US/app/mysearch, the browser was redirected to the default view ｈｔｔｐ://myip/splunk/en-US/app/mysearch/dashboard1. Next, when i drilled down from dashboard1 or changed menu to dashboard2 or other operations, i aperiodically got "401 Unauthorized" errors and was kicked back to ｈｔｔｐ://myip/splunk/en-US/app/search/dashboard many times.&lt;/P&gt;

&lt;P&gt;From firebug, i got the following 2 kinds of responses for "401 unauthorized":&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;1) Splunk cannot authenticate the request. CSRF validation failed.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;2) No permission -- see authorization schemes&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;when i requested the following addresses&lt;/P&gt;

&lt;P&gt;a)
ｈｔｔｐ://myip/splunk/en-US/app/mysearch/flashtimeline/_current?FlashTimeline_0_5_0.minimized=false&lt;/P&gt;

&lt;P&gt;b)
ｈｔｔｐ://myip/splunk/en-US/api/search/jobs?auto_cancel=90&amp;amp;earliest_time=-4h%40h&amp;amp;latest_time=now&amp;amp;namespace=mysearch&amp;amp;search=search%20eventtype%3D%22*-TEST-*%22%20%7C%20timechart%20count%20as%20Total&amp;amp;status_buckets=0&amp;amp;ui_dispatch_app=mysearch&amp;amp;ui_dispatch_view=dashboard2&lt;/P&gt;

&lt;P&gt;c)
ｈｔｔｐ://myip/splunk/en-US/api/messages/index.&lt;/P&gt;

&lt;P&gt;d)
.......&lt;/P&gt;

&lt;P&gt;I think we should login as user "admin" in default and have all permissions in free splunk. And i got nothing about "CSRF validation failed" and "authorization schemes" in this forum and from google. Can anyone give me some suggestions about this?&lt;/P&gt;

&lt;P&gt;Thanks &amp;amp; Best Regards.&lt;/P&gt;

&lt;P&gt;Dianbo&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2010 08:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12839#M244</guid>
      <dc:creator>dianbo_1</dc:creator>
      <dc:date>2010-05-04T08:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: 401 Unauthorized! Why?</title>
      <link>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12840#M245</link>
      <description>&lt;P&gt;my non-answer suggestions, hopefully someone else will know more:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;investigate if you've got a proxy involved here somewhere. It's possible the CSRF header isn't doing what it should with providing the right values.&lt;/LI&gt;
&lt;LI&gt;use some sort of sniffer to see the http headers provided for the working and nonworking requests.&lt;/LI&gt;
&lt;LI&gt;get a baseline with splunk/en-US/debug/echo&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 05 May 2010 13:14:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12840#M245</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-05-05T13:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: 401 Unauthorized! Why?</title>
      <link>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12841#M246</link>
      <description>&lt;P&gt;Yes. This happens constantly on certain systems, on 4.1.5 as well as the new 4.2 beta. It happens to me every 5 minutes or so.   I've been reporting it pretty regularly for months but I havent heard any updates.  I'm still not sure what combination of factors is present to make it easier to reproduce but on some browsers/networks/splunkInstances it's REALLY easy to reproduce and on a lot of systems it's impossible.   &lt;/P&gt;

&lt;P&gt;I've debugged and troubleshooted it quite thoroughly.  Here are some answers posts from other people suffering from the bug. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/questions/5242/firefox-cannot-stay-logged-in-to-splunk" rel="nofollow"&gt;http://answers.splunk.com/questions/5242/firefox-cannot-stay-logged-in-to-splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/questions/5501/browser-session-timing-out-quickly-and-inconsistently" rel="nofollow"&gt;http://answers.splunk.com/questions/5501/browser-session-timing-out-quickly-and-inconsistently&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2010 05:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/401-Unauthorized-Why/m-p/12841#M246</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2010-12-16T05:10:40Z</dc:date>
    </item>
  </channel>
</rss>

