<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed search error on GUI configuration: entry not saved in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316593#M11954</link>
    <description>&lt;P&gt;There is no search involved here.  What do you mean?&lt;/P&gt;</description>
    <pubDate>Mon, 04 Sep 2017 17:01:04 GMT</pubDate>
    <dc:creator>landen99</dc:creator>
    <dc:date>2017-09-04T17:01:04Z</dc:date>
    <item>
      <title>Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316591#M11952</link>
      <description>&lt;P&gt;After entering the search peer information into the Distributed Search-Add search peers window, I get the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Your entry was not saved. The following error was reported: SyntaxError: Unexpected token &amp;lt; in JSON at position 0.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My URI is:&lt;BR /&gt;
&lt;A href="https://192.168.###.###:8089"&gt;https://192.168.###.###:8089&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then when I try to search "index=_internal sourcetype=splunkd error | head 99", I get the error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Splunk cannot authenticate the request. CSRF validation failed.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What could the issue be and how should I troubleshoot this one?&lt;/P&gt;

&lt;P&gt;A quick note about my server.conf in etc\system\local, the current setting is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sslConfig]
enableSplunkdSSL = false
sslPassword = $1$MhI5x3Z+VX7R
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk keeps adding sslpassword even though I have enable splunkdssl set to false, despite stopping splunk to edit the file.  At one point, I tried encryption and tried to back out of it when it didn't work as I had expected.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 00:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316591#M11952</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2017-09-04T00:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316592#M11953</link>
      <description>&lt;P&gt;I don't know about the 2nd error, but the first one is a bug which is easily worked-around:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/106487/your-entry-was-not-saved-the-following-error-was-r.html"&gt;https://answers.splunk.com/answers/106487/your-entry-was-not-saved-the-following-error-was-r.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 16:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316592#M11953</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-09-04T16:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316593#M11954</link>
      <description>&lt;P&gt;There is no search involved here.  What do you mean?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 17:01:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316593#M11954</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2017-09-04T17:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316594#M11955</link>
      <description>&lt;P&gt;Did you see this answer about browser plugins?&lt;/P&gt;

&lt;P&gt;Ref: &lt;A href="https://answers.splunk.com/answers/247389/cant-add-input-for-rest-ta-your-entry-was-not-save-1.html"&gt;https://answers.splunk.com/answers/247389/cant-add-input-for-rest-ta-your-entry-was-not-save-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I think I got this error once and I went into the DMC setup page and without making any changes, clicked on save configuration and it fixed the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 01:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316594#M11955</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-09-05T01:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316595#M11956</link>
      <description>&lt;P&gt;Hi @ landen99,&lt;/P&gt;

&lt;P&gt;Can u help with how u addressed the second CSRF issue ? I am facing a similar issue.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 08:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316595#M11956</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-01-16T08:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316596#M11957</link>
      <description>&lt;P&gt;Both SH and IDX must be set to either encrypt or not.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 20:51:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316596#M11957</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2018-01-16T20:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search error on GUI configuration: entry not saved</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316597#M11958</link>
      <description>&lt;P&gt;Thanks!!!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 08:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-error-on-GUI-configuration-entry-not-saved/m-p/316597#M11958</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-01-17T08:11:14Z</dc:date>
    </item>
  </channel>
</rss>

