The Splunk integration fails to authenticate with Splunk using token-based authentication after configuration information for the token has been changed (such as the name or audience settings).
The updated configuration information for the token no longer matches the cached token used by the integration.
Remove the cached token and restart the Splunk integration to force it to fetch a fresh token from Splunk:
- Stop the StackState Agent
- Locate the directory /opt/stackstate-agent/run
- Rename (or backup and remove) the file called splunk_topologyCheckData.pickle
- Restart the StackState Agent
Article is closed for comments.