<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forgot Pass4symmKey in Security</title>
    <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379012#M11506</link>
    <description>&lt;P&gt;Thanks! You are entirely correct! I had the wrong port.&lt;/P&gt;

&lt;P&gt;My particular setup used port 9997 for the GUI, and looking around further I found the value of &lt;EM&gt;mgmtHostPort&lt;/EM&gt; in my local/web.conf. Using that value, I can get the REST API to work from a console.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I  do get XML responses&lt;/STRONG&gt; about passwords, but no passwords. I used, e.g., /servicesNS/-/-/storage/passwords/. I also tried to access /servicesNS/-/-/storage/passwords/general and /servicesNS/-/-/storage/passwords/:general:, &lt;EM&gt;but got a "could not find" response&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;At this point, however, I have to put this aside since I have the answer I was seeking by using the script I reference above.&lt;/P&gt;

&lt;P&gt;I suspect that part of the problem following the original recipe may be that I am running 6.3.2; the file passwords.conf was only created in 6.5.2 and above.&lt;/P&gt;

&lt;P&gt;Thanks again, rvany and scheng both, for your invaluable help solving this puzzle.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2019 14:52:17 GMT</pubDate>
    <dc:creator>myudkowsky</dc:creator>
    <dc:date>2019-12-04T14:52:17Z</dc:date>
    <item>
      <title>Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378993#M11487</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Is their any way to decrypt splunk encrypted-pass4symmkey or else will splunk team support for the &lt;BR /&gt;plain text pass4symmkey&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 02:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378993#M11487</guid>
      <dc:creator>nerelluk</dc:creator>
      <dc:date>2020-06-07T02:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378994#M11488</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;Its better if you change pass4symmkey and stored it securely somewhere for future use. &lt;/P&gt;

&lt;P&gt;Although below blog give script to decrypt password, you can give a try:&lt;BR /&gt;
&lt;A href="https://www.hurricanelabs.com/splunk-tutorials/make-splunk-do-it-how-to-decrypt-passwords-encrypted-by-splunk"&gt;https://www.hurricanelabs.com/splunk-tutorials/make-splunk-do-it-how-to-decrypt-passwords-encrypted-by-splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 04:23:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378994#M11488</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-12-26T04:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378995#M11489</link>
      <description>&lt;P&gt;Thanks Gurav&lt;/P&gt;

&lt;P&gt;It means a lot!!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 09:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378995#M11489</guid>
      <dc:creator>nerelluk</dc:creator>
      <dc:date>2018-12-27T09:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378996#M11490</link>
      <description>&lt;P&gt;Please accept answer if its helpful!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 10:24:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378996#M11490</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-12-27T10:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378997#M11491</link>
      <description>&lt;P&gt;Hi Gurav&lt;/P&gt;

&lt;P&gt;when i am adding  a new sever to the licensemaster i am getting the following error...&lt;/P&gt;

&lt;P&gt;"&lt;STRONG&gt;Splunkd daemon is not responding: ("Error connecting to /services/licenser/localslave/license: ('The read operation timed out',)",)"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;i had done for the pass4syymkey...but what about the SSL...?&lt;/P&gt;

&lt;P&gt;Hope the issue might reslove&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2018 05:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378997#M11491</guid>
      <dc:creator>nerelluk</dc:creator>
      <dc:date>2018-12-28T05:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378998#M11492</link>
      <description>&lt;P&gt;when i am about to accept answer it is throwing an error ..&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 06:00:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378998#M11492</guid>
      <dc:creator>nerelluk</dc:creator>
      <dc:date>2019-01-03T06:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378999#M11493</link>
      <description>&lt;P&gt;&lt;STRONG&gt;From Splunk version 7.2.2 and above&lt;/STRONG&gt;, you may run below command to decrypt the encrypted password to find the original clear text password on the same splunk instance:&lt;BR /&gt;
*&lt;EM&gt;./splunk show-decrypted --value '&amp;lt; pass4SymmKey &amp;gt;'  *&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.2/Security/ConfigureS2Sonnewcipher"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.2/Security/ConfigureS2Sonnewcipher&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Pre 7.2.2:&lt;/STRONG&gt;&lt;BR /&gt;
You may obtain a clear text password for pass4SymmKey through below steps:&lt;/P&gt;

&lt;P&gt;1) Create passwords.conf in $SPLUNK_HOME/etc/apps/search/local folder&lt;/P&gt;

&lt;P&gt;2) Copy encrypted pass4SymmKey under each stanza in server.conf from CM into passwords.conf:&lt;/P&gt;

&lt;P&gt;Example passwords.conf&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/etc/apps/search/local/passwords.conf&lt;/P&gt;

&lt;P&gt;[credential:general]&lt;BR /&gt;
password = $1$q5jsBxheBw==&lt;/P&gt;

&lt;P&gt;[credential:clustering]&lt;BR /&gt;
password = $1$q5jsBxheBw==&lt;/P&gt;

&lt;P&gt;[credential:license]&lt;BR /&gt;
password = $1$q5jsBxheBw==&lt;/P&gt;

&lt;P&gt;[credential:shclustering]&lt;BR /&gt;
password = $1$q5jsBxheBw==&lt;/P&gt;

&lt;P&gt;3) Run &lt;STRONG&gt;http(s)://server:mgmt_port/en-US/debug/refresh&lt;/STRONG&gt; to read the new configuration&lt;/P&gt;

&lt;P&gt;4) Run &lt;STRONG&gt;http(s)://server:mgmt_port/services/storage/passwords&lt;/STRONG&gt; and look for clear_password for each stanza&lt;/P&gt;

&lt;P&gt;You can also use following format of REST API either through Splunk web or Splunk search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;http(s)://&amp;lt;server&amp;gt;:&amp;lt;mgmt_port&amp;gt;/servicesNS/-/-/storage/passwords
OR
| rest /servicesNS/-/-/storage/passwords
| rest /services/storage/passwords
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 18 Apr 2019 06:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/378999#M11493</guid>
      <dc:creator>scheng_splunk</dc:creator>
      <dc:date>2019-04-18T06:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379000#M11494</link>
      <description>&lt;P&gt;Hi scheng,&lt;/P&gt;

&lt;P&gt;I tired below on Splunk Enterprise version 7.2.5 not working.&lt;BR /&gt;
./splunk show-decrypted --value &amp;lt; pass4SymmKey &amp;gt;&lt;/P&gt;

&lt;P&gt;But other method copying pass4SymmKey to passwords.conf is working.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 08:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379000#M11494</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2019-09-15T08:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379001#M11495</link>
      <description>&lt;P&gt;You have to put single quotes around the key - and in one attempt I had to remove the trailing equal-signs.&lt;/P&gt;

&lt;P&gt;BTW - there's also a &lt;CODE&gt;splunk show-encrypted --value 'topsecret'&lt;/CODE&gt; - which creates strings starting with "$7$" - but I have no idea how/where to use it.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 12:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379001#M11495</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2019-09-20T12:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379002#M11496</link>
      <description>&lt;P&gt;Thanks for informing that i need to put pass4SymmKey in quotes.&lt;/P&gt;

&lt;P&gt;I will try and post the results here.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 13:04:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379002#M11496</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2019-09-20T13:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379003#M11497</link>
      <description>&lt;P&gt;When I try the pre-7.x recovery method on version 6.5.x, step 3 does work but step 4 does not: I get a response of&lt;BR /&gt;
    The path '/en-US/services/storage/password' was not found.&lt;BR /&gt;
Note that the '/en-US' was added automatically by Splunk, not me.&lt;/P&gt;

&lt;P&gt;The alternate version of '/servicesNS/-/-/storage/passwords' gives a similar error. '| rest' does not work either when run on the Splunk index head.&lt;/P&gt;

&lt;P&gt;I'm trying to recover the password using a non-critical server; I'd rather not have to use the index head.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 15:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379003#M11497</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2019-11-12T15:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379004#M11498</link>
      <description>&lt;P&gt;you have to run the REST API with the passwords.conf on the same Splunk instance which you're trying to decrypt the pass4SymmKey since the splunk.secret key file used for encryption is different on each Splunk instance. It's autogenerated during splunk installation.&lt;/P&gt;

&lt;P&gt;You can test the procedure on a dev instance first with same procedure before doing so in production.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 23:57:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379004#M11498</guid>
      <dc:creator>scheng_splunk</dc:creator>
      <dc:date>2019-11-12T23:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379005#M11499</link>
      <description>&lt;P&gt;First and foremost, thank you for your update.&lt;/P&gt;

&lt;P&gt;I tried the REST API on the same Splunk instance I had passwords.conf installed, and I got no response at all.&lt;/P&gt;

&lt;P&gt;In addition, the URL&lt;BR /&gt;
     http(s)://server:mgmt_port/services/storage/passwords&lt;BR /&gt;
 on my installation immediately add an en-US and does not display anything. &lt;/P&gt;

&lt;P&gt;I will try some variations on this; I have a suspicion that I may need to run this on the licensing master.&lt;/P&gt;

&lt;P&gt;If I figure this out I'll post my comments here.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 21:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379005#M11499</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2019-11-13T21:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379006#M11500</link>
      <description>&lt;P&gt;After putting this aside for a while -- some urgent projects -- I have tried again today, and it still does not work for me.&lt;/P&gt;

&lt;P&gt;I've tried this several times -- on the same server that has the passwords I want to decipher -- and I still can't get it to work. Password refresh does work, that is, debug/refresh gives me a results page, and I do see:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Refreshing admin/passwords OK&lt;BR /&gt;
on the page that comes up. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;When I try "services/storage/passwords" I get the same error as before: an added "/en-US" in the path and a 404. When I try to use the rest API via search, I get no errors but no results. &lt;/P&gt;

&lt;P&gt;I find that no /services APIs work. E.g., /services/server/health_report and similar innocuous REST API  attempts, both via HTTP and via "|rest", all fail. /server/info fails. /search/apps/local does work via '| rest.'&lt;/P&gt;

&lt;P&gt;I am now trying to figure out why /server and /services both fail. I wonder if it's related to a privilege issue, but I'm logging in as admin.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 15:10:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379006#M11500</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2019-12-03T15:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379007#M11501</link>
      <description>&lt;P&gt;Just to cut this out: which port are you using as management port?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 17:21:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379007#M11501</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2019-12-03T17:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379008#M11502</link>
      <description>&lt;P&gt;My management port is 9997; I'm running Splunk 6.2.1 that was installed as part of an Aspect install of Prophecy.&lt;/P&gt;

&lt;P&gt;After a great deal of additional attempts, I now find that the REST API works:&lt;BR /&gt;
    | rest /services/storage&lt;BR /&gt;
 gives the result&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;author  id  published   splunk_server   title   updated
system  &lt;A href="https://127.0.0.1/services/storage/collections" target="test_blank"&gt;https://127.0.0.1/services/storage/collections&lt;/A&gt;      &amp;lt;deleted&amp;gt;   collections     2019-12-03T15:34:19+00:00
system  &lt;A href="https://127.0.0.1/services/storage/passwords" target="test_blank"&gt;https://127.0.0.1/services/storage/passwords&lt;/A&gt;        &amp;lt;deleted&amp;gt;   passwords   2019-12-03T15:34:19+00:00 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but asking for the passwords via "| rest /services/storage/passwords" fails, and I wonder if it 's related to lack of HTTPS access.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 18:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379008#M11502</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2019-12-03T18:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379009#M11503</link>
      <description>&lt;P&gt;And now I have HTTPS running, and it makes no difference. I also added &lt;EM&gt;list_storage_passwords&lt;/EM&gt; to authorize.conf -- it was not there before -- but regardless I cannot access the passwords from either search or over the net. &lt;/P&gt;

&lt;P&gt;I have a strong suspicion that it's been disabled somehow. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379009#M11503</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2020-09-30T03:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379010#M11504</link>
      <description>&lt;P&gt;This tool works perfectly: &lt;A href="https://pypi.org/project/splunksecrets/"&gt;https://pypi.org/project/splunksecrets/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 19:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379010#M11504</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2019-12-03T19:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379011#M11505</link>
      <description>&lt;P&gt;9997 - in a default installation - is the port you use for incoming data, e.g. from your Universal Forwarders. The management port - in a default installation - which you use to access the REST API using your browser is 8089. Using that no "en-US" will be added to your URL.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 05:59:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379011#M11505</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2019-12-04T05:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Forgot Pass4symmKey</title>
      <link>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379012#M11506</link>
      <description>&lt;P&gt;Thanks! You are entirely correct! I had the wrong port.&lt;/P&gt;

&lt;P&gt;My particular setup used port 9997 for the GUI, and looking around further I found the value of &lt;EM&gt;mgmtHostPort&lt;/EM&gt; in my local/web.conf. Using that value, I can get the REST API to work from a console.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I  do get XML responses&lt;/STRONG&gt; about passwords, but no passwords. I used, e.g., /servicesNS/-/-/storage/passwords/. I also tried to access /servicesNS/-/-/storage/passwords/general and /servicesNS/-/-/storage/passwords/:general:, &lt;EM&gt;but got a "could not find" response&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;At this point, however, I have to put this aside since I have the answer I was seeking by using the script I reference above.&lt;/P&gt;

&lt;P&gt;I suspect that part of the problem following the original recipe may be that I am running 6.3.2; the file passwords.conf was only created in 6.5.2 and above.&lt;/P&gt;

&lt;P&gt;Thanks again, rvany and scheng both, for your invaluable help solving this puzzle.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 14:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forgot-Pass4symmKey/m-p/379012#M11506</guid>
      <dc:creator>myudkowsky</dc:creator>
      <dc:date>2019-12-04T14:52:17Z</dc:date>
    </item>
  </channel>
</rss>

