<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New forwarder: An Admin password is required??? in Security</title>
    <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414989#M13117</link>
    <description>&lt;P&gt;I would not leave it default...it may not be used often but it can be exploited for bad things.  For example, somebody connecting to it with the default username/password, pointing it to a rogue deployment server, pushing down scripts to run in context of the splunk user and possibly owning the box. &lt;/P&gt;

&lt;P&gt;On the UF's, we set a random password for the admin account and disable the management port.&lt;/P&gt;

&lt;P&gt;Have a look at this .conf session from a couple years back:&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/files/2016/recordings/universal-forwarder-security-dont-input-more-than-data-into-your-splunk-environment.mp4"&gt;https://conf.splunk.com/files/2016/recordings/universal-forwarder-security-dont-input-more-than-data-into-your-splunk-environment.mp4&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2019 17:17:43 GMT</pubDate>
    <dc:creator>maciep</dc:creator>
    <dc:date>2019-04-19T17:17:43Z</dc:date>
    <item>
      <title>New forwarder: An Admin password is required???</title>
      <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414984#M13112</link>
      <description>&lt;P&gt;Running V7.1, but just Installed a new forwarder and received this response:   This appears to be your first time running this version of Splunk.  An Admin password must be set before installation proceeds. Password must contain at least:    * 8 total printable ASCII character(s). Please enter a new password:  Please confirm new password:; Is this a new feature? What password is being requested? &lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 17:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414984#M13112</guid>
      <dc:creator>dpapenbro</dc:creator>
      <dc:date>2018-05-22T17:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: New forwarder: An Admin password is required???</title>
      <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414985#M13113</link>
      <description>&lt;P&gt;From v7.1, Splunk requires you to set the admin password, because else people tend to stick with &lt;CODE&gt;changeme&lt;/CODE&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
You can put in whatever password you like, but make sure to remember it.&lt;/P&gt;

&lt;P&gt;Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2018 19:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414985#M13113</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-22T19:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: New forwarder: An Admin password is required???</title>
      <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414986#M13114</link>
      <description>&lt;P&gt;when do we even use this forwarder admin/pass?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 20:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414986#M13114</guid>
      <dc:creator>vvedanta</dc:creator>
      <dc:date>2019-04-18T20:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: New forwarder: An Admin password is required???</title>
      <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414987#M13115</link>
      <description>&lt;P&gt;On a forwarder it's rare that I've used it, other than checking the status of the tailingProcessor and such.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2011/01/02/did-i-miss-christmas-2.html"&gt;https://www.splunk.com/blog/2011/01/02/did-i-miss-christmas-2.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 20:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414987#M13115</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2019-04-18T20:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: New forwarder: An Admin password is required???</title>
      <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414988#M13116</link>
      <description>&lt;P&gt;So its ok leave it to default in that case?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 15:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414988#M13116</guid>
      <dc:creator>vvedanta</dc:creator>
      <dc:date>2019-04-19T15:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: New forwarder: An Admin password is required???</title>
      <link>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414989#M13117</link>
      <description>&lt;P&gt;I would not leave it default...it may not be used often but it can be exploited for bad things.  For example, somebody connecting to it with the default username/password, pointing it to a rogue deployment server, pushing down scripts to run in context of the splunk user and possibly owning the box. &lt;/P&gt;

&lt;P&gt;On the UF's, we set a random password for the admin account and disable the management port.&lt;/P&gt;

&lt;P&gt;Have a look at this .conf session from a couple years back:&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/files/2016/recordings/universal-forwarder-security-dont-input-more-than-data-into-your-splunk-environment.mp4"&gt;https://conf.splunk.com/files/2016/recordings/universal-forwarder-security-dont-input-more-than-data-into-your-splunk-environment.mp4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 17:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-forwarder-An-Admin-password-is-required/m-p/414989#M13117</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2019-04-19T17:17:43Z</dc:date>
    </item>
  </channel>
</rss>

