Splunk Enterprise

Getting "Your Session is Invalid. Please login" when running splunk command

afears
Engager

Hi all,

I'm running into the error "Your session is invalid. Please login." everytime I try to run a "splunk" command.

For example, I've hit this error when trying to run the following commands:

  • splunk validate cluster-bundle --check-restart
  • splunk reload deploy-server

I've tried entering both credentials for user "splunk" as well as administrative credentials, but it usually says something like, "login failed, failed to contact the master. ERROR: call not properly authenticated."

This is something new, and I'm trying to figure out what changed.

Any help would be greatly appreciated!

Thanks in advance.

Tags (1)
0 Karma

jplumsdaine22
Influencer

The credentials are for the user in splunk itself, rather than the host. Are you using LDAP, SSO or local authentication for your splunk instance?

You should be able to get a handle on why the login is failing with index=_internal sourcetype=splunkd ERROR usernameThatsFailing . The actual component will depend on your authentication type

0 Karma

jplumsdaine22
Influencer

The credentials are for the user in splunk itself, rather than the host. Are you using LDAP, SSO or local authentication for your splunk instance?

You should be able to get a handle on why the login is failing with index=_internal sourcetype=splunkd ERROR usernameThatsFailing . The actual component will depend on your authentication type

0 Karma

afears
Engager

Thank you for the help; that was a great place to look. It seems like the authentication error is tied to a failure in ldap.

jplumsdaine22
Influencer

No problem. If that worked for you would mind accepting the answer?

Cheers,

JP

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...