Splunk Enterprise

restore user token

schose
Builder

Hi all,

we are currently testing desaster recovery of our enviroment. We have a full backup of kvstore, apps and passwd for the searchhead instance.

We are using local technical users using tokens to authenticate and edit kvstores using rest api.  In the backup we found system/JsonWebTokensV1/JsonWebTokensV10.json and restored that. Now we see tokens in the gui, but getting 500 errors when trying to log in using the tokens. The json structure of the kvstore backup only seems to hold meta information about the token, like description and id. 

But where are the token actually are stored? What file information have to be recovered on a complete new instance?

Thanks for your help in advance,

Andreas

Tags (2)
0 Karma
1 Solution

schose
Builder

answer: double- and triplecheck that splunk.secret is set to the correct value. 😉

View solution in original post

0 Karma

schose
Builder

answer: double- and triplecheck that splunk.secret is set to the correct value. 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...