Splunk Search

Installing app in SplunkWeb Manager: error occurred while downloading the app: [HTTP 403] Client is not authorized to perform requested action

jbsplunk
Splunk Employee
Splunk Employee

I have access to Splunk.com without issue.

However when I try to install any app such as SoS and Sideview Utils, from within SplunkWeb > Manager > Apps > Find More Apps Online > select Install Free,
I, and other users, get the following errors:

An error occurred while downloading the app: [HTTP 403] Client is not authorized to perform requested action; https://127.0.0.1:8089/services/apps/remote/entriesbyid/sos

An error occurred while downloading the app: [HTTP 403] Client is not authorized to perform requested action; https://127.0.0.1:8089/services/apps/remote/entriesbyid/sideview_utils
Tags (1)
1 Solution

Ellen
Splunk Employee
Splunk Employee

It was determined the default admin and power roles were modified to disable the following capabilities.

in $SPLUNK_HOME/etc/system/local/authorize.conf

[role_admin]
rest_apps_management = disabled

[role_power]
rest_properties_set = disabled

To install the apps in SplunkWeb's Manager > Apps, change these capabilities from disabled to enabled.

It is recommended the defaults for the admin role especially remain as Splunk provides and instead create a new custom admin role where modifications to the capabilities are made.
Appropriate users can then be assigned this custom role.
This way you are ensured that the admin role remains fully functional by default.

View solution in original post

danmccarthy
Engager

I am experiencing this same issue, and this solution does not solve the problem, as both of those properties are set to "enabled". I am running a trial enterprise license of v 5.0.3 on OSX 10.9.3.

Installing manually as a workaround worked for me, although it'd be a lot simpler if this feature worked as intended. The workaround was just to download the app from splunk.com, then click App->Manage Apps-->Install app from file, and follow the prompts, including a splunk restart.

0 Karma

Ellen
Splunk Employee
Splunk Employee

It was determined the default admin and power roles were modified to disable the following capabilities.

in $SPLUNK_HOME/etc/system/local/authorize.conf

[role_admin]
rest_apps_management = disabled

[role_power]
rest_properties_set = disabled

To install the apps in SplunkWeb's Manager > Apps, change these capabilities from disabled to enabled.

It is recommended the defaults for the admin role especially remain as Splunk provides and instead create a new custom admin role where modifications to the capabilities are made.
Appropriate users can then be assigned this custom role.
This way you are ensured that the admin role remains fully functional by default.

dina_vaghjiani
New Member

Our configuration doesn't have a file of that name in the config. Is it a case of just creating one?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...

Index This | What is feather-light but cannot be held long?

May 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

.conf26 Registration is Live: Secure Your Early Bird Pass Now

  Lock in Your Spot: Registration Open for .conf26 in Denver Hello Splunkers, I have exciting news! Your ...