Dashboards & Visualizations

HTTPAuthManager - Token not specified in Authorization: Splunk header

redc
Builder

Every 5-10 minutes, I see this error pop up in the splunkd.log:

WARN HTTPAuthManager - Token not specified in Authorization: Splunk <token> header

I'm seeing this on my older, well-established Splunk server (Windows 2008 R2) as well as my new server (Linux CentOS). The Linux server has Splunk, Splunk DB Connect, Sideview Utils, Splunk on Splunk, and the Splunk Deployment Monitor installed, all using default configurations. The only customization on the Linux server so far is enabling Single Sign-On and a custom root_endpoint.

We are replacing the Windows server with the Linux server; we did a poor job of managing errors on the Windows server, so I'm trying to keep on top of the errors with the new Linux server.

Does anyone know what this error means?

jconger
Splunk Employee
Splunk Employee

This looks like a HTTP Event Collector (HEC) message. Are you using HEC? Or, perhaps some devices are trying to send HTTP data to your Splunk instance incorrectly (without the authorization token)?

0 Karma

srcegoff
New Member

Same information as the person below. We are now getting this in a very large quantity and its filling our logs.

27,403 count for the past 15 days. (Math says about one every 45 seconds)

0 Karma

swhite_capfed
New Member

No answer for this yet...? I am seeing these repeatedly in my splunkd.log on 2 indexers and single search head (all Linux FWIW) and I have no idea why. This is basically a brand new installation with only a handful of apps installed. I see this question as well, which also has no answer and seems similar/related (although my splunkd service stays running, unlike in this question):

http://answers.splunk.com/answers/140435/splunkd-service-stopping-intermittently-after-upgrading-to-...

Any ideas exactly what this error means or what is causing it?

0 Karma

fabiocaldas
Contributor

I'm facing this same WARN here in my Splunk 6.2.2 cluster and have no clues about it

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...