Deployment Architecture

Distributed search error on GUI configuration: entry not saved

landen99
Motivator

After entering the search peer information into the Distributed Search-Add search peers window, I get the following error:

Your entry was not saved. The following error was reported: SyntaxError: Unexpected token < in JSON at position 0.

My URI is:
https://192.168.###.###:8089

Then when I try to search "index=_internal sourcetype=splunkd error | head 99", I get the error:

Splunk cannot authenticate the request. CSRF validation failed.

What could the issue be and how should I troubleshoot this one?

A quick note about my server.conf in etc\system\local, the current setting is:

[sslConfig]
enableSplunkdSSL = false
sslPassword = $1$MhI5x3Z+VX7R

Splunk keeps adding sslpassword even though I have enable splunkdssl set to false, despite stopping splunk to edit the file. At one point, I tried encryption and tried to back out of it when it didn't work as I had expected.

0 Karma

deepashri_123
Motivator

Hi @ landen99,

Can u help with how u addressed the second CSRF issue ? I am facing a similar issue.

0 Karma

landen99
Motivator

Both SH and IDX must be set to either encrypt or not.

0 Karma

deepashri_123
Motivator

Thanks!!!

0 Karma

jkat54
SplunkTrust
SplunkTrust

Did you see this answer about browser plugins?

Ref: https://answers.splunk.com/answers/247389/cant-add-input-for-rest-ta-your-entry-was-not-save-1.html

I think I got this error once and I went into the DMC setup page and without making any changes, clicked on save configuration and it fixed the problem.

0 Karma

woodcock
Esteemed Legend

I don't know about the 2nd error, but the first one is a bug which is easily worked-around:
https://answers.splunk.com/answers/106487/your-entry-was-not-saved-the-following-error-was-r.html

0 Karma

landen99
Motivator

There is no search involved here. What do you mean?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...