<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk cannot authenticate the request. CSRF validation failed. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/559252#M6371</link>
    <description>&lt;P&gt;Thanks. Did not want to clear everything, so tried in-private mode which also seemed to let me complete ES install.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 11:55:21 GMT</pubDate>
    <dc:creator>CSmoke</dc:creator>
    <dc:date>2021-07-13T11:55:21Z</dc:date>
    <item>
      <title>Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296363#M714</link>
      <description>&lt;P&gt;i tray to install splunk light new version and it looks good the installation, but when i tray to sing and change the default password i get this error:&lt;BR /&gt;Splunk cannot authenticate the request. CSRF validation failed.&lt;/P&gt;
&lt;P&gt;When i tray to change http to https configuration i get this error:&lt;BR /&gt;Your entry was not saved. The following error was reported: SyntaxError: Unexpected token &amp;lt; in JSON at position 0.&lt;/P&gt;
&lt;P&gt;in the log i get this error.&lt;BR /&gt;10-12-2017 19:35:29.532 -0500 ERROR UiAuth - Request from 10.1.94.11 to "/en-GB/splunkd/__raw/servicesNS/admin/search/search/jobs" failed CSRF validation -- expected "17589544990277644692", but instead cookie had "" and header had ""&lt;/P&gt;
&lt;P&gt;someone know how to correct...??&lt;BR /&gt;thanks for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 22:33:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296363#M714</guid>
      <dc:creator>tomasnelson</dc:creator>
      <dc:date>2020-06-09T22:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296364#M715</link>
      <description>&lt;P&gt;you probably have a cookie in cache with parameters in conflict with your current splunk configuration (either because you reinstalled and it was http at a time or change some related settings which make the cookie like it could have been tampered by a attacker)&lt;BR /&gt;
just remove cookies for that site from your browser cache and try again, that usually fix this kind of CRSF error message behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 03:32:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296364#M715</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2017-10-13T03:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296365#M716</link>
      <description>&lt;P&gt;&lt;STRONG&gt;THANKS A LOT!!!!&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;you answer resolved my problem...... &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;very thankful&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 14:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296365#M716</guid>
      <dc:creator>tomasnelson</dc:creator>
      <dc:date>2017-10-13T14:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296366#M717</link>
      <description>&lt;P&gt;I got the same error while loading a UI app and resolved after clearing the cache.&lt;BR /&gt;
Thanks!!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 05:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296366#M717</guid>
      <dc:creator>pbankar</dc:creator>
      <dc:date>2019-01-14T05:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296367#M718</link>
      <description>&lt;P&gt;If you are experiencing this in Chrome and have a recent version of Chrome where the option to search for cookies by site seems to have been skillfully hidden leaving you with the option to nuke all your cookies (which you may not want to do) - then you can resolve the issue as follows ...&lt;/P&gt;

&lt;P&gt;open chrome&lt;BR /&gt;
enter the following into the address bar&lt;BR /&gt;
chrome://settings/siteData&lt;BR /&gt;
enter the host/splunk instance in the search bar to locate any cookies&lt;BR /&gt;
delete&lt;/P&gt;

&lt;P&gt;That should fix the issue. (Just did it myself for the same reason).&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 16:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296367#M718</guid>
      <dc:creator>ddas_splunk</dc:creator>
      <dc:date>2019-04-19T16:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296368#M719</link>
      <description>&lt;P&gt;You may want to check this doc which suggests 2 X-headers are mandatory.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Cookie: splunkd_PORT=splunkd_cookie;splunkweb_csrf_token_PORT=csrf_token,
Content-type: application/json,
X-Requested-With: XMLHttpRequest,
X-Splunk-Form-Key: csrf_token
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You will find more details in the doc below;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.1.3/DeployStreamApp/SplunkAppforStreamRESTAPI"&gt;https://docs.splunk.com/Documentation/StreamApp/7.1.3/DeployStreamApp/SplunkAppforStreamRESTAPI&lt;/A&gt;&lt;BR /&gt;
Or check this one as well;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/772850/custom-api-endpoint-returning-csrf-error-on-post.html"&gt;https://answers.splunk.com/answers/772850/custom-api-endpoint-returning-csrf-error-on-post.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 17:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296368#M719</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2019-10-11T17:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296369#M720</link>
      <description>&lt;P&gt;Thank you very much for this answer which solved my problem after googling revealed this thread. Any reason these are the docs for the Splunk App for Stream? I'm under the impression this is a Splunk Enterprise feature.&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 05:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/296369#M720</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2020-05-08T05:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot authenticate the request. CSRF validation failed.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/559252#M6371</link>
      <description>&lt;P&gt;Thanks. Did not want to clear everything, so tried in-private mode which also seemed to let me complete ES install.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 11:55:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-cannot-authenticate-the-request-CSRF-validation-failed/m-p/559252#M6371</guid>
      <dc:creator>CSmoke</dc:creator>
      <dc:date>2021-07-13T11:55:21Z</dc:date>
    </item>
  </channel>
</rss>

