<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Token Not Work in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749077#M22537</link>
    <description>Thank you for your advice, I ignored the token content and cloesd it.</description>
    <pubDate>Wed, 02 Jul 2025 05:26:50 GMT</pubDate>
    <dc:creator>chenfan</dc:creator>
    <dc:date>2025-07-02T05:26:50Z</dc:date>
    <item>
      <title>Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749001#M22525</link>
      <description>&lt;P&gt;Hi Splunker,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I tried to enable/disable with API, but I encountered problems with token authentication. I always get the following error. I have also adjusted the API information, but I still can't solve this problem.&lt;BR /&gt;&lt;BR /&gt;curl -v -X POST -k -H "Authorization: Bearer dc73xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" "&lt;A href="https://mysplunkserver:8089/servicesNS/nobody/my_app/saved/searches/testalertapi" target="_blank"&gt;https://mysplunkserver:8089/servicesNS/nobody/my_app/saved/searches/testalertapi&lt;/A&gt;" -d enabled=0&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chenfan_0-1751353950663.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39531iA002DF5BB970190B/image-size/large?v=v2&amp;amp;px=999" role="button" title="chenfan_0-1751353950663.png" alt="chenfan_0-1751353950663.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chenfan_1-1751353981697.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39532i6BFD912B39F014A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chenfan_1-1751353981697.png" alt="chenfan_1-1751353981697.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It will be really great if you could share some working examples somewhere in your documentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 07:15:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749001#M22525</guid>
      <dc:creator>chenfan</dc:creator>
      <dc:date>2025-07-01T07:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749003#M22526</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251661"&gt;@chenfan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two types of token, one is a JWT token that you can create in the UI via the Tokens page (Bearer). The other is by logging in to the &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/RESTUM/RESTusing#:~:text=server.conf%20file.-,Authentication%20with%20HTTP%20Authorization%20tokens,-The%20API%20supports" target="_self"&gt;/services/auth/login&lt;/A&gt; endpoint and retrieving a session token..&lt;/P&gt;&lt;P&gt;Based on your short token length I suspect you are using a session token (and JWT tokens often start "eyJ") which means the Authorization type should be "Splunk" not "Bearer"&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Bearer: Means to use a bearer token header, the standard for Javascript Object Notation (JSON) Web Tokens (JWTs), on which Splunk authentication tokens are based.
Splunk: Means to use the Splunk header for authentication.&lt;/LI-CODE&gt;&lt;P&gt;Try the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -v -X POST -k -H "Authorization: Splunk dc73xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" "https://mysplunkserver:8089/servicesNS/nobody/my_app/saved/searches/testalertapi" -d enabled=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 07:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749003#M22526</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-01T07:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749011#M22527</link>
      <description>&lt;P&gt;Hi @&lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906" target="_self"&gt;&lt;SPAN class=""&gt;livehybrid&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thankyou for your reply!&lt;BR /&gt;&lt;BR /&gt;I have tried,but it not work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chenfan_0-1751359554172.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39533i3FFB7EDC6EB75054/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chenfan_0-1751359554172.png" alt="chenfan_0-1751359554172.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And this is my token&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chenfan_0-1751359773644.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39535i7C49D4BBE5FA0948/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chenfan_0-1751359773644.png" alt="chenfan_0-1751359773644.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 09:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749011#M22527</guid>
      <dc:creator>chenfan</dc:creator>
      <dc:date>2025-07-01T09:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749012#M22528</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251661"&gt;@chenfan&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Any error messages on splunkd.log?&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can also refer #&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.3/authenticate-into-the-splunk-platform-with-tokens/troubleshoot-token-authentication" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.3/authenticate-into-the-splunk-platform-with-tokens/troubleshoot-token-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you create another token with admin account and test the same.&lt;/P&gt;&lt;P&gt;Also test without token,&lt;BR /&gt;curl -k -u admin:yourpassword &lt;A href="https://mysplunkserver:8089/servicesNS/nobody/my_app/saved/searches/testalertapi" target="_blank"&gt;https://mysplunkserver:8089/servicesNS/nobody/my_app/saved/searches/testalertapi&lt;/A&gt; -d enabled=0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 09:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749012#M22528</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-01T09:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749020#M22529</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251661"&gt;@chenfan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That string starting dc736 is *not* your token. This is the token ID.&lt;/P&gt;&lt;P&gt;Its not possible to retrieve the token once created so copy it somewhere safe. If using this type of token then you will need to set use "Bearer" as you were doing before.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="livehybrid_0-1751367354228.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39536iE83BF38B76B2C737/image-size/medium?v=v2&amp;amp;px=400" role="button" title="livehybrid_0-1751367354228.png" alt="livehybrid_0-1751367354228.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 10:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749020#M22529</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-01T10:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749076#M22536</link>
      <description>Yep，I can use useraccount&amp;amp;password to do it.</description>
      <pubDate>Wed, 02 Jul 2025 05:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749076#M22536</guid>
      <dc:creator>chenfan</dc:creator>
      <dc:date>2025-07-02T05:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Token Not Work</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749077#M22537</link>
      <description>Thank you for your advice, I ignored the token content and cloesd it.</description>
      <pubDate>Wed, 02 Jul 2025 05:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Authorization-Token-Not-Work/m-p/749077#M22537</guid>
      <dc:creator>chenfan</dc:creator>
      <dc:date>2025-07-02T05:26:50Z</dc:date>
    </item>
  </channel>
</rss>

