Splunk Enterprise

Python Error After Upgrading from 8.2.2.1 to 9.0.2

splunkkitty
Path Finder

Our Dev Splunk instance was recently upgraded from Splunk Enterprise 8.2.2.1 to 9.0.2.

I am getting the following error on our primary Search Head from python.log on splunkd restart:


ERROR config:149 - [HTTP 401] Client is not authenticated Traceback (most recent call last): File "/opt/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/lib/config.py", line 147, in getServerZoneInfoNoMem return times.getServerZoneinfo() File "/opt/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/lib/times.py", line 163, in getServerZoneinfo serverStatus, serverResp = splunk.rest.simpleRequest('/search/timeparser/tz', sessionKey=sessionKey) File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 625, in simpleRequest raise splunk.AuthenticationFailed splunk.AuthenticationFailed: [HTTP 401] Client is not authenticated


I did a re-scan of everything using the newest version of the Upgrade Readiness App (off Splunkbase). Some apps did have a Python warning. I verified currently installed versions of each app (with the exception of Splunk Enterprise package-included apps like Splunk Secure Gateway and Splunk RapidDiag) and the documentation states our installed versions are compatible with Enterprise 9.0. It does not appear that any installed apps are using a deprecated version of python.

I also ran the following command and verified our python version as Python 3.7.11:
splunk cmd python -V

After combing over known issues for the 9.0 release
and other Answers threads I’ve had no luck. I don’t know if this errors is meaningful so direction would be advised.

Thank you!

Labels (2)
0 Karma

terry_berryhill
Loves-to-Learn Lots

I am getting the same errors on my hf's, did you get any assistance on this?

0 Karma

splunkkitty
Path Finder

Hey, @terry_berryhill!

The 401 errors are expected when Splunk restarts and the web client attempts to reconnect using old cookies. According to Splunk support the 401 errors can be safely ignored.

Issue number:
SPL-206763

Hope this helps!

0 Karma

terry_berryhill
Loves-to-Learn Lots

It appears that when we upgraded from 8.2.2.1 to 9.0.2 Splunk assist was turned on.  We turned off Splunk Assist (we do not have Splunk Cloud services)  the errors stopped.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...