I keep getting Client is not authenticated Error.
I wondered if there was an error occurring internally, so I confirmed that the following authentication error occurred while searching.
startup:116 - Unable to read in product version information; isSessionKeyDefined=False error=[HTTP 401] Client is not authenticated
Host: It seems to be occurring in both IDX and SH, and it is confirmed that the error occurred on 11/12.
Is there any way to check which app is causing it?
I see this error on 9.1.5 However i'm curious what effect does this error have on the splunk, does it make splunk search page unreachable?
I see following while loading webpage, is this because of above error?
Hmm... cant reach this page
connection was reset.
I don't recall exactly what fixed this, but I would hazard the guess it's to do with the sslPassword in server.conf
I reached out to Splunk Support regarding this issue and they mentioned that this is associated with a known issue(SPL-245333), this is not fixed yet but the expected version will be until 9.3. So, it is understandable why we would still see it in current versions. If they are so annoying in logs, you might blacklist those events.
https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392
I'm seeing this same error on a new build. Did you ever find an answer?