<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk reload auth in Search head Error in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711377#M21622</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271699"&gt;@Sathish28&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; said, please check this.&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;[capability::change_authentication]&lt;/SPAN&gt;&lt;/H3&gt;&lt;PRE&gt;* Lets a user change authentication settings through the authentication endpoints.
* Lets the user reload authentication.&lt;/PRE&gt;&lt;P&gt;and also,&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to work to reload it, and is available through the management port.&lt;/P&gt;&lt;PRE&gt;curl -k -u admin:changeme https://splunkserver:8089/services/authentication/providers/services/_reload&lt;/PRE&gt;&lt;P&gt;You can use this simple Splunk command to do this:&lt;/P&gt;&lt;PRE&gt;./splunk _internal call /authentication/providers/services/_reload -auth&lt;/PRE&gt;&lt;PRE&gt;&amp;nbsp;QUERYING: 'https://127.0.0.1:8089/services/authentication/providers/services/_reload'&lt;BR /&gt;Your session is invalid. Please login.&lt;BR /&gt;Splunk username: &lt;BR /&gt;Password:&lt;BR /&gt;HTTP Status: 200.&lt;BR /&gt;Content:&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;&amp;lt;feed xmlns="http://www.w3.org/2005/Atom" xmlns:s="http://dev.splunk.com/ns/rest" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/"&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;auth-services&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;id&amp;gt;https://127.0.0.1:8089/services/authentication/providers/services&amp;lt;/id&amp;gt;&lt;BR /&gt;&amp;lt;updated&amp;gt;2014-04-02T08:39:45+02:00&amp;lt;/updated&amp;gt;&lt;BR /&gt;&amp;lt;generator build="163460" version="5.0.3"/&amp;gt;&lt;BR /&gt;&amp;lt;author&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;/author&amp;gt;&lt;BR /&gt;&amp;lt;link href="/services/authentication/providers/services/_reload" rel="_reload"/&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:totalResults&amp;gt;0&amp;lt;/opensearch:totalResults&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:itemsPerPage&amp;gt;30&amp;lt;/opensearch:itemsPerPage&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:startIndex&amp;gt;0&amp;lt;/opensearch:startIndex&amp;gt;&lt;BR /&gt;&amp;lt;s:messages/&amp;gt;&lt;BR /&gt;&amp;lt;/feed&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2025 15:32:23 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-02-12T15:32:23Z</dc:date>
    <item>
      <title>Splunk reload auth in Search head Error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711372#M21618</link>
      <description>&lt;P&gt;Recently we migrated a server from Virtual Machine to Physical server&lt;BR /&gt;We use LDAP authentication for user access for Splunk&lt;BR /&gt;The users were able to login but did not have the same privileges when moved from VM to physical server&lt;BR /&gt;&lt;BR /&gt;I am able to login into Splunk Web UI but as a admin I am not able to view with admin privileges, So i tried to run the below command in the search head server&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;./splunk reload auth&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;I got the below error&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Authorization Failed: b'&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;\n&amp;lt;response&amp;gt;\n&amp;nbsp; &amp;lt;messages&amp;gt;\n&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;msg type="ERROR"&amp;gt;You (user=88888888) do not have permission to perform this operation (requires capability: change_authentication).&amp;lt;/msg&amp;gt;\n&amp;nbsp; &amp;lt;/messages&amp;gt;\n&amp;lt;/response&amp;gt;\n'&lt;BR /&gt;Client is not authorized to perform requested action&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 15:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711372#M21618</guid>
      <dc:creator>Sathish28</dc:creator>
      <dc:date>2025-02-12T15:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk reload auth in Search head Error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711374#M21620</link>
      <description>&lt;P&gt;It looks like your user role doesnt have `&lt;SPAN&gt;change_authentication = enabled` which is required for this task.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you have access to an admin account, or maybe a break-glass account that you can execute the CLI reload with?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 15:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711374#M21620</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-02-12T15:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk reload auth in Search head Error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711377#M21622</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271699"&gt;@Sathish28&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp; said, please check this.&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;[capability::change_authentication]&lt;/SPAN&gt;&lt;/H3&gt;&lt;PRE&gt;* Lets a user change authentication settings through the authentication endpoints.
* Lets the user reload authentication.&lt;/PRE&gt;&lt;P&gt;and also,&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to work to reload it, and is available through the management port.&lt;/P&gt;&lt;PRE&gt;curl -k -u admin:changeme https://splunkserver:8089/services/authentication/providers/services/_reload&lt;/PRE&gt;&lt;P&gt;You can use this simple Splunk command to do this:&lt;/P&gt;&lt;PRE&gt;./splunk _internal call /authentication/providers/services/_reload -auth&lt;/PRE&gt;&lt;PRE&gt;&amp;nbsp;QUERYING: 'https://127.0.0.1:8089/services/authentication/providers/services/_reload'&lt;BR /&gt;Your session is invalid. Please login.&lt;BR /&gt;Splunk username: &lt;BR /&gt;Password:&lt;BR /&gt;HTTP Status: 200.&lt;BR /&gt;Content:&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;&amp;lt;feed xmlns="http://www.w3.org/2005/Atom" xmlns:s="http://dev.splunk.com/ns/rest" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/"&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;auth-services&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;id&amp;gt;https://127.0.0.1:8089/services/authentication/providers/services&amp;lt;/id&amp;gt;&lt;BR /&gt;&amp;lt;updated&amp;gt;2014-04-02T08:39:45+02:00&amp;lt;/updated&amp;gt;&lt;BR /&gt;&amp;lt;generator build="163460" version="5.0.3"/&amp;gt;&lt;BR /&gt;&amp;lt;author&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;/author&amp;gt;&lt;BR /&gt;&amp;lt;link href="/services/authentication/providers/services/_reload" rel="_reload"/&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:totalResults&amp;gt;0&amp;lt;/opensearch:totalResults&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:itemsPerPage&amp;gt;30&amp;lt;/opensearch:itemsPerPage&amp;gt;&lt;BR /&gt;&amp;lt;opensearch:startIndex&amp;gt;0&amp;lt;/opensearch:startIndex&amp;gt;&lt;BR /&gt;&amp;lt;s:messages/&amp;gt;&lt;BR /&gt;&amp;lt;/feed&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 15:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-reload-auth-in-Search-head-Error/m-p/711377#M21622</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-02-12T15:32:23Z</dc:date>
    </item>
  </channel>
</rss>

