<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with thread management session? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27373#M6809</link>
    <description>&lt;P&gt;It's been a long time and I honestly don't recall anymore &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Give it a shot and see? Let us know what you find out?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2015 12:08:05 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2015-06-30T12:08:05Z</dc:date>
    <item>
      <title>Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27367#M6803</link>
      <description>&lt;P&gt;I saw this issue on multiple browsers.&lt;/P&gt;

&lt;P&gt;I have splunk fronted by four reverse proxy servers running IBM HTTP Server 7.0.0.17 (Apache 2.2.8) presenting SiteMinder as a SSO agent.&lt;/P&gt;

&lt;P&gt;To debug/verify the setup on each individual web server, I navigate to http://&lt;HOSTNAME&gt;.company.com:&lt;LISTENPORT&gt;.  This prompts me to log in as expected.  I am then able to use any non search related feature in splunk.  By that, I mean that I can navigate to the manager but if I navigate to search I am redirected to the native splunk login page.&lt;/LISTENPORT&gt;&lt;/HOSTNAME&gt;&lt;/P&gt;

&lt;P&gt;I see this activity corresponding in the logs:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;2013-02-11 09:10:00,976 INFO    [5118fbb8ea4e379d0] cached:77 - memoized decorator used on function &amp;lt;function getEntities at 0x4258cf8&amp;gt; with non hashable arguments&lt;BR /&gt;
2013-02-11 09:10:01,336 INFO    [5118fbb9465007c90] cached:77 - memoized decorator used on function &amp;lt;function getEntities at 0x4258cf8&amp;gt; with non hashable arguments&lt;BR /&gt;
2013-02-11 09:10:01,774 INFO    [5118fbb9465007c90] view:1070 - PERF - viewTime=0.2188s templateTime=0.2196s&lt;BR /&gt;
2013-02-11 09:10:03,112 ERROR   [5118fbbb175115150] utility:125 - [HTTP 401] Client is not authenticated&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/appserver/mrsparkle/controllers/utility.py", line 123, in parse_time&lt;BR /&gt;
    parsed = times.splunktime2Iso(ts)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/appserver/mrsparkle/lib/times.py", line 173, in splunktime2Iso&lt;BR /&gt;
    serverStatus, serverResp = splunk.rest.simpleRequest('/search/timeparser', getargs=getargs)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/rest/__init__.py", line 452, in simpleRequest&lt;BR /&gt;
    raise splunk.AuthenticationFailed&lt;BR /&gt;
AuthenticationFailed: [HTTP 401] Client is not authenticated&lt;BR /&gt;
2013-02-11 09:10:03,365 WARNING [5118fbbb59563d2d0] util:1255 - CSRF form_key mismatch received=14808273786252083278 expected=None&lt;BR /&gt;
2013-02-11 09:10:03,367 WARNING [5118fbbb59563d2d0] decorators:87 - CSRF: validation failed because client XHR did not include proper header&lt;BR /&gt;
2013-02-11 09:10:03,376 WARNING [5118fbbb5c50e0890] util:1255 - CSRF form_key mismatch received=14808273786252083278 expected=None&lt;BR /&gt;
2013-02-11 09:10:03,378 WARNING [5118fbbb5c50e0890] decorators:87 - CSRF: validation failed because client XHR did not include proper header&lt;BR /&gt;
2013-02-11 09:10:03,570 WARNING [5118fbbb8f4caa190] util:1255 - CSRF form_key mismatch received=14808273786252083278 expected=None&lt;BR /&gt;
2013-02-11 09:10:03,570 WARNING [5118fbbb8f4caa190] decorators:87 - CSRF: validation failed because client XHR did not include proper header&lt;BR /&gt;
2013-02-11 09:10:03,738 WARNING [5118fbbbb750eb310] util:1255 - CSRF form_key mismatch received=14808273786252083278 expected=None&lt;BR /&gt;
2013-02-11 09:10:03,740 WARNING [5118fbbbb750eb310] decorators:87 - CSRF: validation failed because client XHR did not include proper header&lt;BR /&gt;
2013-02-11 09:10:03,742 WARNING [5118fbbbb750eb310] decorators:95 - CSRF: skipping 401 redirect response because endpoint did not request protection&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This does NOT occur when navigating to splunk with my dns/VIP which load balances amongst the four web servers with a sticky session.&lt;/P&gt;

&lt;P&gt;I am aware that there is a domain requirement on my SOS policy that requires *.company.com.&lt;/P&gt;

&lt;P&gt;I'm not sure how to phrase my question, or if I'm using the right terms.  My SOS engineer suggests I research how the session is passed from thread to thread (given my interpretation that search spawns another thread).&lt;/P&gt;

&lt;P&gt;Any idea why I am being redirected back to the login page?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2013 14:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27367#M6803</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-02-11T14:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27368#M6804</link>
      <description>&lt;P&gt;Try hitting the &lt;CODE&gt;/debug/sso&lt;/CODE&gt; endpoint and see what you get back. It should tell you what is being passed by the Proxy.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2013 21:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27368#M6804</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2013-02-11T21:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27369#M6805</link>
      <description>&lt;P&gt;Thanks. I checked there but I'm not confident with the results I've found. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I did find the following:&lt;BR /&gt;
 - In the working scenario, I have a Cookie with a session_id_39002.  This is missing from the broken one.  39002 is my splunk httpport.&lt;BR /&gt;
 - In the working scenario, X-Forwarded-Host is splunk.company.com, hostname.company.com:listenport in the broken scenario.&lt;BR /&gt;
 - As expected, the User listed in Server info: footer of the working scenario is my user ID, but 'UNKNOWN_USER' in the broken scenario.&lt;BR /&gt;
All other values match.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27369#M6805</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2020-09-28T13:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27370#M6806</link>
      <description>&lt;P&gt;So you don't have anything in the Value of Remote-User section or Is the incoming request IP in splunkweb's list of trustedIPs?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2013 15:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27370#M6806</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2013-02-12T15:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27371#M6807</link>
      <description>&lt;P&gt;I found the issue - not so much an issue, more a feature.&lt;/P&gt;

&lt;P&gt;tools.sessions.secure in web.conf, by default, restricts session to only https.  By connecting directly to my reverse proxy, I was not using an https connection, but rather an http.&lt;/P&gt;

&lt;P&gt;I proved this by setting tools.sessions.secure = False and was able to connect.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2013 22:13:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27371#M6807</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-02-13T22:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27372#M6808</link>
      <description>&lt;P&gt;Hi - I have a similar issue. did setting the tools.session.secure = False alone was enough?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 06:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27372#M6808</guid>
      <dc:creator>lakshman237</dc:creator>
      <dc:date>2015-06-30T06:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with thread management session?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27373#M6809</link>
      <description>&lt;P&gt;It's been a long time and I honestly don't recall anymore &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Give it a shot and see? Let us know what you find out?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 12:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Issues-with-thread-management-session/m-p/27373#M6809</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2015-06-30T12:08:05Z</dc:date>
    </item>
  </channel>
</rss>

