Illegal cookie name

Path Finder

I think this is similar to but not exactly.

It seems that when I have a domain wide cookie set, I can never get to splunk (if I use a fully qualified domain name to access splunk).

Even if the cookie names appear valid, I still get an error from splunk. Here is one example.

400 Bad Request

Illegal cookie name AtworkEnv

Traceback (most recent call last): File "/opt/splunk/splunk/lib/python2.6/site-packages/cherrypy/", line 581, in respond self.process_headers() File "/opt/splunk/splunk/lib/python2.6/site-packages/cherrypy/", line 653, in process_headers raise cherrypy.HTTPError(400, msg) HTTPError: (400, 'Illegal cookie name AtworkEnv')

The domain wide cookies are set by an ap that we have no control over (and must goto daily). Also, I must use a fully qualified domain name to access splunk (we have different domain at my work).

Has anyone found a workaround for this?



Tags (3)

Path Finder

So, I'm gathering that the workarounds to this issue are as follows:

1) Clear cookies, and try again


2) Use Firefox (which has worked for me).

Am I correct? Is there anything else I can tell my Splunk users?



Just wanted to say THANK YOU for this!! I've had this illegal cookie issue for MONTHS, and so far everyone I've bothered to help me looked at me like I have two heads... Firefox WORKS!!! 🙂


Any progress on handling the illegal cookies?
Cherrypy just forbid me from accessing Splunk frontend after accessing a Zabbix instance on the same server:

'Illegal cookie name cb_/zabbix/items.php_parts'

0 Karma

Path Finder

Bump. This just bit me again, this time with glassfish admin cookies.

This is a problem somewhere in

Anyone have a little fix? Maybe something borrowed from a newer Python? I see on the tubes that this is a problem for Google Analytics, as well, as they use cookies with colons in the name.


It looks like commenting out line 653 will stop the error from killing the request. I will make sure this is filed as a bug with CherryPy.

Path Finder

This does not seem to work reliably.
The stops processing (and raises the error) when it hits the first error.
So if the "Cookie" header contains:
good=value; b:ad=value
Things are fine with that line commented out.
If the value of "Cookie" is:
b:ad=value; good=value
Then stops processing and the good=value is never read in.
I think we need to comment out the raise in

0 Karma

Path Finder

Looking at it closer, it appears there are 2 issues:

  • The first is that splunk fails with cookie names with colons in them (like the referenced issue)

  • The second is that splunk is reporting the wrong cookie name when complaining about a cookie

Not sure what we are going to do, but it would be best if splunk could handle the illegal cookie names.

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...