<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting error AuthorizationFailed: [HTTP 403] Client is not authorized to perform requested action in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304124#M36220</link>
    <description>&lt;P&gt;Hi Dev_Choudhary,&lt;/P&gt;

&lt;P&gt;Is your issue resolved?&lt;BR /&gt;
If your issue is resolved, can you share the cause/resolution with us?&lt;/P&gt;

&lt;P&gt;If you are still facing the issue can you provide the answers to below questions:&lt;BR /&gt;
1. What Addon version you are using? &lt;BR /&gt;
2. Have you changed any access rights of existing roles like admin/user/power/splunk-system-role? &lt;BR /&gt;
3. Can you access Splunk management port URL from the browser with admin credentials? (example:   &lt;A href="https://:8089)" target="test_blank"&gt;https://:8089)&lt;/A&gt;&lt;BR /&gt;
4. Also, can you post the contents of Addon's inputs.conf of local? (If any sensitive information is there you can asterisk it before posting.)&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Archana&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jun 2017 08:59:35 GMT</pubDate>
    <dc:creator>ArchanaC</dc:creator>
    <dc:date>2017-06-14T08:59:35Z</dc:date>
    <item>
      <title>Getting error AuthorizationFailed: [HTTP 403] Client is not authorized to perform requested action</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304123#M36219</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;
We have configuring Symantec ATP Add-on to receive Symantec ATP logs on Splunk.&lt;BR /&gt;
We have defined App as ATP and got the Client ID and Client Secret on ATP manager (HTTP event collector already configured), when we are configuring add-on on Splunk HF we are successfully able to authenticate from Symantec ATP.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/190249-capture.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;When searching the logs on Search Head with query sourcetype = Symantec* getting below error &lt;/P&gt;

&lt;P&gt;ERROR 140385235900224 - Symantec ATP Manager: Exception while getting ATP manager host&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-symantec_atp/bin/atp_manager_utility.py", line 110, in get_atp_manager_user_credentials&lt;BR /&gt;
    sessionKey=session_key)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/entity.py", line 129, in getEntities&lt;BR /&gt;
    atomFeed = &lt;EM&gt;getEntitiesAtomFeed(entityPath, namespace, owner, search, count, offset, sort_key, sort_dir, sessionKey, uri, hostPath, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/entity.py", line 222, in _getEntitiesAtomFeed&lt;BR /&gt;
    serverResponse, serverContent = rest.simpleRequest(uri, getargs=kwargs, sessionKey=sessionKey, raiseAllErrors=True)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/rest/&lt;/EM&gt;&lt;EM&gt;init&lt;/EM&gt;_.py", line 516, in simpleRequest&lt;BR /&gt;
    raise splunk.AuthorizationFailed(extendedMessages=uri)&lt;BR /&gt;
AuthorizationFailed: [HTTP 403] Client is not authorized to perform requested action; &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-symantec_atp/storage/passwords?count=-1&amp;amp;search=TA-symantec_atp" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-symantec_atp/storage/passwords?count=-1&amp;amp;search=TA-symantec_atp&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:28:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304123#M36219</guid>
      <dc:creator>Dev_Choudhary</dc:creator>
      <dc:date>2020-09-29T13:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error AuthorizationFailed: [HTTP 403] Client is not authorized to perform requested action</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304124#M36220</link>
      <description>&lt;P&gt;Hi Dev_Choudhary,&lt;/P&gt;

&lt;P&gt;Is your issue resolved?&lt;BR /&gt;
If your issue is resolved, can you share the cause/resolution with us?&lt;/P&gt;

&lt;P&gt;If you are still facing the issue can you provide the answers to below questions:&lt;BR /&gt;
1. What Addon version you are using? &lt;BR /&gt;
2. Have you changed any access rights of existing roles like admin/user/power/splunk-system-role? &lt;BR /&gt;
3. Can you access Splunk management port URL from the browser with admin credentials? (example:   &lt;A href="https://:8089)" target="test_blank"&gt;https://:8089)&lt;/A&gt;&lt;BR /&gt;
4. Also, can you post the contents of Addon's inputs.conf of local? (If any sensitive information is there you can asterisk it before posting.)&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Archana&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 08:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304124#M36220</guid>
      <dc:creator>ArchanaC</dc:creator>
      <dc:date>2017-06-14T08:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error AuthorizationFailed: [HTTP 403] Client is not authorized to perform requested action</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304125#M36221</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Issue  is resolved now. Two possible issues from ATP manager that I can highlights are&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;OAuth Client&lt;/STRONG&gt; name should be &lt;STRONG&gt;ATP&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Time range should be &lt;STRONG&gt;latest&lt;/STRONG&gt; (like last 2 month), default it was taking something from 1990&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 19 Jun 2017 15:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-error-AuthorizationFailed-HTTP-403-Client-is-not/m-p/304125#M36221</guid>
      <dc:creator>Dev_Choudhary</dc:creator>
      <dc:date>2017-06-19T15:33:05Z</dc:date>
    </item>
  </channel>
</rss>

