Security

Why can't I bump Splunk using https:///en-US/_bump and get error message "Forbidden"?

fdarrigo
Path Finder

I am trying to bump a local Splunk instance using : https:///en-US/_bump
but I receive the following:

<response> <messages> <msg type="ERROR">Forbidden</msg> </messages> </response>

This looks like an authentication/authorization error.
I am running Splunk 6.4 (Free license)

What am I doing wrong?

0 Karma
1 Solution

jeffland
Champion

The free license supports neither _bump nor debug/refresh. You'll have to restart your server, as you already noted.

View solution in original post

ppuru
Path Finder

Note that you also have to login before you attempt a successful bump.

0 Karma

jeffland
Champion

The free license supports neither _bump nor debug/refresh. You'll have to restart your server, as you already noted.

Rocket66
Communicator
  • try to got to en-US/info an hit the "Static resource cache control" - same error?
  • try to hit (on the same page ) "EAI object refresh"

btw.: Admin rights?

fdarrigo
Path Finder

I found a work around...
Settings>Server Controls>Restart Splunk

0 Karma

fdarrigo
Path Finder

same results for

en-US/info an hit the "Static resource cache control" - same error?
AND
try to hit (on the same page ) "EAI object refresh"

Since this is the free version, it doesnt support user accounts or roles, so I can't explicitly add myself to a splunk admin role.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...