Splunk Enterprise

Getting "Your Session is Invalid. Please login" when running splunk command

afears
Engager

Hi all,

I'm running into the error "Your session is invalid. Please login." everytime I try to run a "splunk" command.

For example, I've hit this error when trying to run the following commands:

  • splunk validate cluster-bundle --check-restart
  • splunk reload deploy-server

I've tried entering both credentials for user "splunk" as well as administrative credentials, but it usually says something like, "login failed, failed to contact the master. ERROR: call not properly authenticated."

This is something new, and I'm trying to figure out what changed.

Any help would be greatly appreciated!

Thanks in advance.

Tags (1)
0 Karma

jplumsdaine22
Influencer

The credentials are for the user in splunk itself, rather than the host. Are you using LDAP, SSO or local authentication for your splunk instance?

You should be able to get a handle on why the login is failing with index=_internal sourcetype=splunkd ERROR usernameThatsFailing . The actual component will depend on your authentication type

0 Karma

jplumsdaine22
Influencer

The credentials are for the user in splunk itself, rather than the host. Are you using LDAP, SSO or local authentication for your splunk instance?

You should be able to get a handle on why the login is failing with index=_internal sourcetype=splunkd ERROR usernameThatsFailing . The actual component will depend on your authentication type

0 Karma

afears
Engager

Thank you for the help; that was a great place to look. It seems like the authentication error is tied to a failure in ldap.

jplumsdaine22
Influencer

No problem. If that worked for you would mind accepting the answer?

Cheers,

JP

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...