Splunk Enterprise

Getting "Your Session is Invalid. Please login" when running splunk command

afears
Engager

Hi all,

I'm running into the error "Your session is invalid. Please login." everytime I try to run a "splunk" command.

For example, I've hit this error when trying to run the following commands:

  • splunk validate cluster-bundle --check-restart
  • splunk reload deploy-server

I've tried entering both credentials for user "splunk" as well as administrative credentials, but it usually says something like, "login failed, failed to contact the master. ERROR: call not properly authenticated."

This is something new, and I'm trying to figure out what changed.

Any help would be greatly appreciated!

Thanks in advance.

Tags (1)
0 Karma

jplumsdaine22
Influencer

The credentials are for the user in splunk itself, rather than the host. Are you using LDAP, SSO or local authentication for your splunk instance?

You should be able to get a handle on why the login is failing with index=_internal sourcetype=splunkd ERROR usernameThatsFailing . The actual component will depend on your authentication type

0 Karma

jplumsdaine22
Influencer

The credentials are for the user in splunk itself, rather than the host. Are you using LDAP, SSO or local authentication for your splunk instance?

You should be able to get a handle on why the login is failing with index=_internal sourcetype=splunkd ERROR usernameThatsFailing . The actual component will depend on your authentication type

0 Karma

afears
Engager

Thank you for the help; that was a great place to look. It seems like the authentication error is tied to a failure in ldap.

jplumsdaine22
Influencer

No problem. If that worked for you would mind accepting the answer?

Cheers,

JP

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...