Security

Why can't I bump Splunk using https:///en-US/_bump and get error message "Forbidden"?

fdarrigo
Path Finder

I am trying to bump a local Splunk instance using : https:///en-US/_bump
but I receive the following:

<response> <messages> <msg type="ERROR">Forbidden</msg> </messages> </response>

This looks like an authentication/authorization error.
I am running Splunk 6.4 (Free license)

What am I doing wrong?

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

The free license supports neither _bump nor debug/refresh. You'll have to restart your server, as you already noted.

View solution in original post

ppuru
Path Finder

Note that you also have to login before you attempt a successful bump.

0 Karma

jeffland
SplunkTrust
SplunkTrust

The free license supports neither _bump nor debug/refresh. You'll have to restart your server, as you already noted.

Rocket66
Communicator
  • try to got to en-US/info an hit the "Static resource cache control" - same error?
  • try to hit (on the same page ) "EAI object refresh"

btw.: Admin rights?

fdarrigo
Path Finder

I found a work around...
Settings>Server Controls>Restart Splunk

0 Karma

fdarrigo
Path Finder

same results for

en-US/info an hit the "Static resource cache control" - same error?
AND
try to hit (on the same page ) "EAI object refresh"

Since this is the free version, it doesnt support user accounts or roles, so I can't explicitly add myself to a splunk admin role.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...