<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunkd.log: Denied session token for user: splunk-system-user in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41770#M2003</link>
    <description>&lt;P&gt;have you changed your admin passwords recently and is the search head using the correct admin user of the indexer ? &lt;BR /&gt;
I believe this refers to invalid authentication between search peer and indexer and can be setup in the search peers part of the management console.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2011 11:57:21 GMT</pubDate>
    <dc:creator>anttih</dc:creator>
    <dc:date>2011-10-12T11:57:21Z</dc:date>
    <item>
      <title>splunkd.log: Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41769#M2002</link>
      <description>&lt;P&gt;My indexers started throwing this:&lt;/P&gt;

&lt;P&gt;07-02-2011 04:00:58.307 -0300 WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user&lt;/P&gt;

&lt;P&gt;07-02-2011 04:01:05.551 -0300 WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user&lt;/P&gt;

&lt;P&gt;As a result, I get an error on the Search Heads stating that it has "skipped indexing of internal audit event will keep dropping events..."&lt;/P&gt;

&lt;P&gt;The last time I got this warning at the Search Heads it was due to the optimization taking too long, but this one is new to me, any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2011 18:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41769#M2002</guid>
      <dc:creator>Stefan</dc:creator>
      <dc:date>2011-07-12T18:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log: Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41770#M2003</link>
      <description>&lt;P&gt;have you changed your admin passwords recently and is the search head using the correct admin user of the indexer ? &lt;BR /&gt;
I believe this refers to invalid authentication between search peer and indexer and can be setup in the search peers part of the management console.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2011 11:57:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41770#M2003</guid>
      <dc:creator>anttih</dc:creator>
      <dc:date>2011-10-12T11:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log: Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41771#M2004</link>
      <description>&lt;P&gt;Invalid authentication between the search peers and the search head distributing search to these peers would result in an 'Authenication Failed' type of message. This error indicates something is wrong with the token. That the search peer is sending back something in its header requesting access via an invalid token. It could also be related to time I suppose. Have you looked at splunkd_access.log to see if there are any errors in that file?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2011 18:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41771#M2004</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-11-14T18:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log: Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41772#M2005</link>
      <description>&lt;P&gt;It may be due to an edition of distsearch.conf without establishing trusts (indexers must trust searchhead's certificates) so you can fix this problem by following what's written in this &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Configuredistributedsearch#Edit_distsearch.conf"&gt;paragraph&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2013 09:39:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41772#M2005</guid>
      <dc:creator>yoho</dc:creator>
      <dc:date>2013-05-29T09:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd.log: Denied session token for user: splunk-system-user</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41773#M2006</link>
      <description>&lt;P&gt;Incorrect. The search head only uses the admin password of the indexer once - to send over a certificate. The certificate is used in Distributed Search from there on, so it does not matter if any password is changed on the indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2014 20:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunkd-log-Denied-session-token-for-user-splunk-system-user/m-p/41773#M2006</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2014-10-21T20:03:33Z</dc:date>
    </item>
  </channel>
</rss>

