<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Event Collector: How to resolve a &amp;quot;401 Unauthorized from Splunk&amp;quot; error when trying to pass token in query string? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/HTTP-Event-Collector-How-to-resolve-a-quot-401-Unauthorized-from/m-p/257013#M16116</link>
    <description>&lt;P&gt;This appears to be a Splunk Cloud feature. It's listed on the Splunk Cloud inputs.conf docs at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1612/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1612/Admin/Inputsconf&lt;/A&gt; but not the Splunk Enterprise inputs.conf docs at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Inputsconf&lt;/A&gt; . Also see &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE8Y#tokenasquery"&gt;http://dev.splunk.com/view/event-collector/SP-CAAAE8Y#tokenasquery&lt;/A&gt; which explains that this currently offered in Splunk Cloud and Splunk Light Cloud.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Jan 2017 17:16:35 GMT</pubDate>
    <dc:creator>jtacy</dc:creator>
    <dc:date>2017-01-31T17:16:35Z</dc:date>
    <item>
      <title>HTTP Event Collector: How to resolve a "401 Unauthorized from Splunk" error when trying to pass token in query string?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/HTTP-Event-Collector-How-to-resolve-a-quot-401-Unauthorized-from/m-p/257012#M16115</link>
      <description>&lt;P&gt;I have enabled allowQueryStringAuth as mentioned in &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE8Y#tokenasquery"&gt;http://dev.splunk.com/view/event-collector/SP-CAAAE8Y#tokenasquery&lt;/A&gt; and want to pass my token in the POST request like hxxp://192.168.2.1:8088/services/collector?token= however, i still get a 401 Unauthorized from Splunk.&lt;/P&gt;

&lt;P&gt;A splunk btool check --debug gives me:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tmachielsen@TonsMacBookPro:~% /Applications/Splunk/bin/splunk btool check --debug 
Checking: /Applications/Splunk/etc/users/admin/search/local/ui-prefs.conf
Checking: /Applications/Splunk/etc/users/admin/search/local/ui-tour.conf
Checking: /Applications/Splunk/etc/users/admin/splunk_monitoring_console/local/ui-prefs.conf
Checking: /Applications/Splunk/etc/users/admin/user-prefs/local/user-prefs.conf
Checking: /Applications/Splunk/etc/apps/learned/local/props.conf
Checking: /Applications/Splunk/etc/apps/search/local/indexes.conf
Checking: /Applications/Splunk/etc/apps/search/local/inputs.conf
Checking: /Applications/Splunk/etc/apps/splunk_httpinput/local/inputs.conf
        Invalid key in stanza [http://Speedway Connect] in /Applications/Splunk/etc/apps/splunk_httpinput/local/inputs.conf, line 11: sourcetypeSelection  (value:  From List).
    Did you mean 'sourcetype'?
    Did you mean 'source'?
    Did you mean 'sourcetype'?
        Invalid key in stanza [http://Speedway Connect] in /Applications/Splunk/etc/apps/splunk_httpinput/local/inputs.conf, line 12: allowQueryStringAuth  (value:  true).
Checking: /Applications/Splunk/etc/apps/splunk_instrumentation/local/telemetry.conf
Checking: /Applications/Splunk/etc/apps/user-prefs/local/user-prefs.conf
Checking: /Applications/Splunk/etc/apps/SplunkForwarder/default/app.conf
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any idea what i do wrong?&lt;/P&gt;

&lt;P&gt;Splunk Light 6.5.2 on OSX.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2017 16:35:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/HTTP-Event-Collector-How-to-resolve-a-quot-401-Unauthorized-from/m-p/257012#M16115</guid>
      <dc:creator>PepePelotas</dc:creator>
      <dc:date>2017-01-28T16:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector: How to resolve a "401 Unauthorized from Splunk" error when trying to pass token in query string?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/HTTP-Event-Collector-How-to-resolve-a-quot-401-Unauthorized-from/m-p/257013#M16116</link>
      <description>&lt;P&gt;This appears to be a Splunk Cloud feature. It's listed on the Splunk Cloud inputs.conf docs at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1612/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1612/Admin/Inputsconf&lt;/A&gt; but not the Splunk Enterprise inputs.conf docs at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Inputsconf&lt;/A&gt; . Also see &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE8Y#tokenasquery"&gt;http://dev.splunk.com/view/event-collector/SP-CAAAE8Y#tokenasquery&lt;/A&gt; which explains that this currently offered in Splunk Cloud and Splunk Light Cloud.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 17:16:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/HTTP-Event-Collector-How-to-resolve-a-quot-401-Unauthorized-from/m-p/257013#M16116</guid>
      <dc:creator>jtacy</dc:creator>
      <dc:date>2017-01-31T17:16:35Z</dc:date>
    </item>
  </channel>
</rss>

