<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Downloading lookup files via API returning 403 Forbidden in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/682261#M12404</link>
    <description>&lt;P&gt;Was the issue fixed?&lt;BR /&gt;I'm having the exactly same issue and weeks ago it was working fine.&lt;BR /&gt;&lt;BR /&gt;No change was done to the lookup/dataset permissions and the user I'm using to access is the owner of the lookup.&lt;BR /&gt;&lt;BR /&gt;Could this be related to a splunk certificate being expired?&lt;BR /&gt;or something else?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2024 11:01:21 GMT</pubDate>
    <dc:creator>PTC_</dc:creator>
    <dc:date>2024-03-28T11:01:21Z</dc:date>
    <item>
      <title>Downloading lookup files via API returning 403 Forbidden</title>
      <link>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/665707#M12240</link>
      <description>&lt;P&gt;I just updated the Splunk App for Lookup File Editing to the latest and now I can no longer download lookup files via CLI.&amp;nbsp; This has been working flawlessly in Splunk Cloud when I was running v3.6.0 but just updated to 4.0.1 (v4.0.2 not available in Cloud yet) and now I am getting 403 errors.&lt;/P&gt;&lt;P&gt;Through testing, I verified lookup endpoint is still valid, lookup shared at global level, and I even changed the permissions of the account to be sc_admin but still experiencing the same issue.&amp;nbsp; Has anyone else come across this and found a solution?&amp;nbsp; Same error no matter which lookup file I attempt to download.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My test command&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;python3 lut.py -app search -l geo_attr_countries.csv -app search
INFO:root:list of lookups to download: ['geo_attr_countries.csv']
ERROR:root:[failed] Error: Downloading file: 'geo_attr_countries.csv', status:403, reason:Forbidden, url:https://[REDACTED].splunkcloud.com:8089/services/data/lookup_edit/lookup_contents?lookup_type=csv&amp;amp;namespace=search&amp;amp;lookup_file=geo_attr_countries.csv&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Python script &lt;A href="https://github.com/mthcht/lookup-editor_scripts/blob/main/download_lookups_from_splunk.py" target="_blank" rel="noopener"&gt;from here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 17:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/665707#M12240</guid>
      <dc:creator>random_event</dc:creator>
      <dc:date>2023-10-20T17:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Downloading lookup files via API returning 403 Forbidden</title>
      <link>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/671080#M12319</link>
      <description>&lt;P&gt;You need to supply the owner in your call.&amp;nbsp; Just add "&amp;amp;owner=nobody" if it is a global lookup.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 21:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/671080#M12319</guid>
      <dc:creator>dsanders80</dc:creator>
      <dc:date>2023-12-06T21:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Downloading lookup files via API returning 403 Forbidden</title>
      <link>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/682261#M12404</link>
      <description>&lt;P&gt;Was the issue fixed?&lt;BR /&gt;I'm having the exactly same issue and weeks ago it was working fine.&lt;BR /&gt;&lt;BR /&gt;No change was done to the lookup/dataset permissions and the user I'm using to access is the owner of the lookup.&lt;BR /&gt;&lt;BR /&gt;Could this be related to a splunk certificate being expired?&lt;BR /&gt;or something else?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 11:01:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/682261#M12404</guid>
      <dc:creator>PTC_</dc:creator>
      <dc:date>2024-03-28T11:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Downloading lookup files via API returning 403 Forbidden</title>
      <link>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/682276#M12407</link>
      <description>&lt;P&gt;Unfortunately, I never found a solution.&amp;nbsp; If you happen to find the fix, please reply with it.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 13:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Downloading-lookup-files-via-API-returning-403-Forbidden/m-p/682276#M12407</guid>
      <dc:creator>random_event</dc:creator>
      <dc:date>2024-03-28T13:21:42Z</dc:date>
    </item>
  </channel>
</rss>

