Splunk Cloud Platform

Receiving a 401 Unauthorized error response from ServiceNow

YJ
Explorer

Hi,

Have anyone faced this issue where you received a Unauthorized 401 error response from ServiceNow?

The scenario is as below.

We are using a AD service account userA to interact with ServiceNow for incident creation .

On Splunk Side, we are using Basic Auth.

On AD, user account is set to never expired.  

So far below we have checked the service account status. No changes was made but the issue was sudden.

Ran the query 

>index=_internal sourcetype="ta_snow_ticket host IN ( search head)

Above query was the one, we saw the Return code is 401 (Unauthorized)

What else can be checked? As of now, we are planning to reset the service account password and try again.

But if it works the issue is finding what cause the password to be changed when it have been set to never expires.

 

Labels (2)
0 Karma

PaulPanther
Motivator

Have you verified that the used user has permissions to access ServiceNow via API? You could verify that with postman or a plain curl call.

 

0 Karma

YJ
Explorer

Hi Paul,

That was what I was suspecting, the service account permission to access the Servicenow. The only problem i have is getting the other team(Servicenow) to provide info for my troubleshooting as they are denying that it is their end with issue. I was thinking since the service account is an AD account, there will surely be a security group assign to the service account . I have actually point out that the service account did not have any grouping assigned to it thus there could be a possibility that the servicenow account does not have the permission to access the Servicenow. 

There were actually similar issues where we found that some AD users security group were missing after an issue happened. I will try to go through this path and check on the permission again.. Thanks for the advice.

0 Karma

mjones1
Engager

As a ServiceNow Admin, this is DEFINITELY a problem on the ServiceNow side.  Accounts calling the ServiceNow REST API need to be configured as web service only accounts, and have the correct roles applied based on what you're trying to read.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...