Splunk Search

Why am I getting "Status 401 call not properly authenticated" running a search using the Splunk Java SDK 1.4.0.0?

dimitrkovalsky
Engager

Hello

I am using Splunk java sdk 1.4.0.0 when I execute this query :

String QUERY = "search \"ab_exper\" index=my_apache | rex \".+cohort%7C(?<cohort>.+)%3Bcampaign%7C(?<campaign>.+)%3Brecipe%7C(?<recipe>.+)%3Bplatform.+\" | stats count(recipe) as recipe_count by campaign, recipe";

ServiceArgs loginArgs = new ServiceArgs();
        loginArgs.setUsername(user);
        loginArgs.setPassword(password);
        loginArgs.setHost(splunkHost);
        loginArgs.setPort(port);

        Service service = Service.connect(loginArgs);
        JobArgs jobArgs = new JobArgs();
        jobArgs.setExecutionMode(JobArgs.ExecutionMode.BLOCKING);
        jobArgs.put("earliest_time", dateFormat.format(new Date(from)));
        jobArgs.put("latest_time", dateFormat.format(new Date(to)));

        Job job = service.getJobs().create(QUERY, jobArgs);
        return parseForRawEntries(job);

I receive different errors :
One of them is 401call not properly authenticated. (And I see [Fatal Error] :1:1: Premature end of file. in console)
Another - unexpected end of file from server.
Authentication is success and returns 200 status.

What could be the problem?

Thanks, Dmytro

jnicholsenernoc
Path Finder

I think that error is from when you are hitting splunk web and not splunkd. Make sure you are going against the proper hostname and especially port. Splunk web, on port 80 or 443 or 8000 isn't the same as talking to splunkd on port 8089.

http://dev.splunk.com/view/python-sdk/SP-CAAAEFC

0 Karma

dimitrkovalsky
Engager

It happens when I use earliest_time less than (current - 86400000L) (more than one day).

0 Karma

jnicholsenernoc
Path Finder

I think that error is from when you are hitting splunk web and not splunkd. Make sure you are going against the proper hostname and especially port. Splunk web, on port 80 or 443 or 8000 isn't the same as talking to splunkd on port 8089.

http://dev.splunk.com/view/python-sdk/SP-CAAAEFC

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...