09-20-2021 10:17 AM
I can't seem to connect to the Splunk API that lives on the Reporting server. I've followed the directions from the link below but no matter what account I use I get "incorrect_username_or_passowrd". Tried a read only account as described. The local admin account, and my LDAP account with full admin rights. I've also made sure to open the reporting tab as documented in the link, and my admin group has read write set in Reporting > Administration > Permissions. Any suggessions would be appreciated.
09-21-2021 09:58 AM
Looks like changing the user password breaks something in splunk. Creating a new user to use fixes it. In my first attempt I used a previous read only account that had its password has change.