Introducing SOC Insights for BloxOne Threat Defense: Boost your SOC efficiency with AI-driven insights to eliminate manual work and accelerate investigation and response times. Read the blog announcement here.

API & Integration, DevOps,NetOps,SecOps

Reply

Reporting Server's Splunk API

New Member
Posts: 3
1842     0

I can't seem to connect to the Splunk API that lives on the Reporting server. I've followed the directions from the link below but no matter what account I use I get "incorrect_username_or_passowrd". Tried a read only account as described. The local admin account, and my LDAP account with full admin rights. I've also made sure to open the reporting tab as documented in the link, and my admin group has read write set in Reporting > Administration > Permissions. Any suggessions would be appreciated.

https://community.infoblox.com/t5/Best-Practices/Accessing-Audit-Log-Information-from-the-Reporting-...

 

 

Re: Reporting Server's Splunk API

New Member
Posts: 3
1843     0

Looks like changing the user password breaks something in splunk. Creating a new user to use fixes it. In my first attempt I used a previous read only account that had its password has change.

Showing results for 
Search instead for 
Did you mean: 

Recommended for You