<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145835#M29729</link>
    <description>&lt;P&gt;OK I will try this when I have a moment and see if it fixes the issue. Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2015 09:36:14 GMT</pubDate>
    <dc:creator>Ant1D</dc:creator>
    <dc:date>2015-06-24T09:36:14Z</dc:date>
    <item>
      <title>Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145831#M29725</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a v6.1.6 Windows server 2008 distributed Splunk environment.&lt;BR /&gt;
On the Indexers the following event is being written to splunkd.log every minute:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What could be causing this and how can I make this go away?&lt;/P&gt;

&lt;P&gt;Thanks in advance for your help&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 11:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145831#M29725</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2015-06-09T11:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145832#M29726</link>
      <description>&lt;P&gt;You can fix this by deleting the search head key and directory from the indexer that is reporting the issue.&lt;/P&gt;

&lt;P&gt;On indexer only delete just the search head that is having the issue.&lt;/P&gt;

&lt;P&gt;splunk index&amp;gt; rm -rf /opt/splunk/etc/auth/distServerKeys/mysearchheadhost&lt;/P&gt;

&lt;P&gt;On the search head readd the indexer via the gui.&lt;/P&gt;

&lt;P&gt;This will recreate the directory on the indexer and resend the key across to the index and it should fix this issue.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2015 23:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145832#M29726</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-06-23T23:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145833#M29727</link>
      <description>&lt;P&gt;Hi Lucas, when you say "On the search head readd the indexer via the gui" do you mean add this indexer as a search peer of that search head again?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 08:19:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145833#M29727</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2015-06-24T08:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145834#M29728</link>
      <description>&lt;P&gt;You shouldn't need to readd it as it should still be listed on the search head (you removed it from the indexer only remember). All you need to do is re-auth it. You should see that the replication has failed for that particular search peer. Just click on its name and put in the remote admin/password and click save.&lt;/P&gt;

&lt;P&gt;This will recreate the directory on the indexer and copy across the public key from the search head.&lt;/P&gt;

&lt;P&gt;I did this for 2 indexers today hence me stumbling on this un answered question when I was looking for the solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 09:32:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145834#M29728</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-06-24T09:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145835#M29729</link>
      <description>&lt;P&gt;OK I will try this when I have a moment and see if it fixes the issue. Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 09:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145835#M29729</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2015-06-24T09:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145836#M29730</link>
      <description>&lt;P&gt;I deleted the folder $SPLUNK_HOME/etc/auth/distServerKeys/mysearchheadhost. I did not see a message saying that replication had failed for the indexer. I entered the admin/password and saved but the warning is still there. The warning occurs once a minute on each indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 15:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145836#M29730</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2015-07-13T15:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145837#M29731</link>
      <description>&lt;P&gt;You haven't deleted the right key if you don't get the replication failure.  Double check that you deleted the right one off the indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2015 04:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145837#M29731</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-07-14T04:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145838#M29732</link>
      <description>&lt;P&gt;Mysearchheadhost should be replaced with the name of your actual search head!!! There should be a few directories in there so have a look first (don't cut and paste the command as I posted it)&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2015 04:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145838#M29732</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-07-14T04:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145839#M29733</link>
      <description>&lt;P&gt;mysearchheadhost was replaced with the name of the search head. This is a Windows instance so I did not use your command. I deleted the "mysearchheadhost" directory then I logged in to splunkweb on the search head and re-entered the admin/password details for the indexer in the distributed search peers view. Note, I did not delete the search peer, I just re-entered to admin/password details and "mysearchheadhost" directory re-appeared on the indexer. What is the name of the key that must be deleted? The only key found in "mysearchheadhost" directory is trusted.pem&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2015 08:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/145839#M29733</guid>
      <dc:creator>Ant1D</dc:creator>
      <dc:date>2015-07-14T08:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers showing: WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/510974#M86808</link>
      <description>&lt;P&gt;This happens when you keep cluster master in maintenance mode and re-add peer to cluster. Always ensure you keep cluster master out of maintenance mode when you re-add peer.&lt;BR /&gt;You can simply fix this by going to splunkweb on Search head _ settings_distributed Search_ search peers . Select the peer which is having issues and add the admin user/password _ save&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2020 19:15:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexers-showing-WARN-AdminHandler-AuthenticationHandler-Denied/m-p/510974#M86808</guid>
      <dc:creator>RishiMandal</dc:creator>
      <dc:date>2020-07-25T19:15:15Z</dc:date>
    </item>
  </channel>
</rss>

