I am seeing messages like this:
09-05-2018 13:23:47.416 -0400 WARN AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
09-05-2018 13:23:47.429 -0400 WARN AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
09-05-2018 13:23:47.436 -0400 WARN AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
09-05-2018 13:23:47.436 -0400 WARN AdminHandler:AuthenticationHandler - Denied session token for user: splunk-system-user
Searched for them here but others see the message on search heads, while mine are from a Universal Forwarder, which should not be dispatching any distributed search.
Any thoughts? Thank you for any help.
↧