Getting Data In

user:password combination not working to access REST API via https

joelyon
Explorer

My client has one consistent password for the admin user throughout his Splunk infrastructure. In attempting to show him how to access a UF via the REST API, I attached to the UF using https://xxx.xxx.xxx.xxx:8089 successfully. It displays the web page with the RPC, services, servicesNS and static selections visible. When he selects anyone of them , (services for example), an authentication box pops up and he inputs his "admin" user id along with the system-wide admin password. The box just refreshes and we get no further... No error message, just the authentication box again.... Any clues as to what the issue might be ???

Thanks all....

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

hint:

  • api cannot remotely be accessed with the default password
  • if the new password contains any par of "changeme" is will be considered as not properly changed.
    example : "changeme1".

  • or maybe the password change failed, try the CLI to verify.

0 Karma

Drainy
Champion

Did you try admin:changeme ? In the case that they haven't changed this password.

Also it would be worth looking at the splunkd.log to see if it shows any errors or issues, this is usually quite clear in explaining the problem.

A constantly refreshing login box is usually a sign of incorrect login details though, its worth adding.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...