<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Issue in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505489#M2101</link>
    <description>&lt;P&gt;Sorry, I meant Splunk folder.&amp;nbsp; There is a STIG setting that locks down the permission for Splunk folder.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jun 2020 12:55:58 GMT</pubDate>
    <dc:creator>kchongMITRE</dc:creator>
    <dc:date>2020-06-22T12:55:58Z</dc:date>
    <item>
      <title>Authentication Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505219#M2069</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;I am having some authentication issue.&amp;nbsp; If I run Splunk command in the Command Prompt, I was able to logon as admin.&amp;nbsp; However, when I tried to logon as admin through the web UI, it failed to authenticate.&amp;nbsp; Also, I am not able to logon using my AD account neither.&amp;nbsp; &amp;nbsp;I tried resetting admin password and new password worked in Command Prompt, but not Web UI.&lt;/P&gt;&lt;P&gt;When I looked at the splunkd.log file, I noticed that it has always tried to forward the username (even admin) to LDAP server and then failed saying invalid username.&amp;nbsp; I haven't changed LDAP settings or AD group name or reset the AD account used to bind LDAP (the account is not locked).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how to fix this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 16:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505219#M2069</guid>
      <dc:creator>kchongMITRE</dc:creator>
      <dc:date>2020-06-19T16:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505247#M2077</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Have you tried to force the use of Splunk's local authentication? You can do that using the "?loginType=splunk" after the "/login". Example: https://SPLUNK:8000/en-US/account/login?loginType=splunk&lt;/P&gt;&lt;P&gt;Maybe using this endpoint you will be able to login with your admin user.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 18:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505247#M2077</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-06-19T18:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505488#M2100</link>
      <description>&lt;P&gt;I tried to force using local admin but it will just clear the username and password fields and nothing happened.&amp;nbsp; If I enter the wrong password, then it said "invalid password".&amp;nbsp; Any other clues?&amp;nbsp; Could changing the NTFS permission on the Splunk caused this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 12:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505488#M2100</guid>
      <dc:creator>kchongMITRE</dc:creator>
      <dc:date>2020-06-22T12:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505489#M2101</link>
      <description>&lt;P&gt;Sorry, I meant Splunk folder.&amp;nbsp; There is a STIG setting that locks down the permission for Splunk folder.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 12:55:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authentication-Issue/m-p/505489#M2101</guid>
      <dc:creator>kchongMITRE</dc:creator>
      <dc:date>2020-06-22T12:55:58Z</dc:date>
    </item>
  </channel>
</rss>

