Monitoring Splunk

user login unauthorized error

Path Finder

Hi ,

ERROR UiAuth - user= action=login status=failure reason=sso-failed useragent="Mozilla/5.0 (Windowxxxxxxxx64; x64) AppleWxxxxxxxxML, like Gecko) Chrome/64.0.3282.137.36" clientip=10.2xxx6
action = login host = xxx SHC index = _internal message = user= action=login status=failure reason=sso-failed useraxxxxxindows NT 6.1; WinxxxxxKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.186 Safari/537.36" clientip=10xxxx8.6 reason = sso-failed

Tags (1)
0 Karma


Hi @shraddhamuduli

Please go through this splunk answer & give it a try


0 Karma

New Member

I am facing same issue, Is there any pointers on this issue?

0 Karma

Splunk Employee
Splunk Employee

It seems the person who opened this issue didn't provide feedback on the answers posted. Have you opened a support case if it's not working as documented?

0 Karma

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...