Getting Data In

On Forwarder: WARN AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user

ww9rivers
Contributor

I am seeing messages like this:

09-05-2018 13:23:47.416 -0400 WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
09-05-2018 13:23:47.429 -0400 WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
09-05-2018 13:23:47.436 -0400 WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
09-05-2018 13:23:47.436 -0400 WARN  AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user

Searched for them here but others see the message on search heads, while mine are from a Universal Forwarder, which should not be dispatching any distributed search.

Any thoughts? Thank you for any help.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...