Dashboards & Visualizations

HTTPAuthManager - Token not specified in Authorization: Splunk header


Every 5-10 minutes, I see this error pop up in the splunkd.log:

WARN HTTPAuthManager - Token not specified in Authorization: Splunk <token> header

I'm seeing this on my older, well-established Splunk server (Windows 2008 R2) as well as my new server (Linux CentOS). The Linux server has Splunk, Splunk DB Connect, Sideview Utils, Splunk on Splunk, and the Splunk Deployment Monitor installed, all using default configurations. The only customization on the Linux server so far is enabling Single Sign-On and a custom root_endpoint.

We are replacing the Windows server with the Linux server; we did a poor job of managing errors on the Windows server, so I'm trying to keep on top of the errors with the new Linux server.

Does anyone know what this error means?

Splunk Employee
Splunk Employee

This looks like a HTTP Event Collector (HEC) message. Are you using HEC? Or, perhaps some devices are trying to send HTTP data to your Splunk instance incorrectly (without the authorization token)?

0 Karma

New Member

Same information as the person below. We are now getting this in a very large quantity and its filling our logs.

27,403 count for the past 15 days. (Math says about one every 45 seconds)

0 Karma

New Member

No answer for this yet...? I am seeing these repeatedly in my splunkd.log on 2 indexers and single search head (all Linux FWIW) and I have no idea why. This is basically a brand new installation with only a handful of apps installed. I see this question as well, which also has no answer and seems similar/related (although my splunkd service stays running, unlike in this question):


Any ideas exactly what this error means or what is causing it?

0 Karma


I'm facing this same WARN here in my Splunk 6.2.2 cluster and have no clues about it

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...