Getting Data In

Authorization Failed: [HTTP 403] Client is not authorized to perform requested action

wildbill4
Path Finder

New to Splunk.... Was in the role section and deleted the User role and now I am getting the error "Authorization Failed: [HTTP 403] Client is not authorized to perform requested action". Any clue how to correct? Thanks

Tags (1)
1 Solution

Rob
Splunk Employee
Splunk Employee

You may also want to check if the user role has the capability "rest_properties_get" as this error can occur if the default Splunk authentication is in use and this capability is missing.

View solution in original post

Rob
Splunk Employee
Splunk Employee

You may also want to check if the user role has the capability "rest_properties_get" as this error can occur if the default Splunk authentication is in use and this capability is missing.

wildbill4
Path Finder

I had to go into the Authorize.conf file and change the "disabled" from true to false. Then I was able to login

Branden
Builder

Do you mean you can no longer log in to Splunk at all, even as the admin user? If you can log in as admin, what happens when you try to re-create the User role?

wildbill4
Path Finder

Thanks for the input

0 Karma

Branden
Builder

Oooh. I'm not sure how to advise you in that case. I was going to suggest simply re-creating the User role via the manager. I believe there's a way to do it from the file system without logging in. Perhaps someone on here will know the answer to that.

0 Karma

wildbill4
Path Finder

I am unable to login as admin.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...