<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Login reset Spl in Security</title>
    <link>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627931#M16547</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253141"&gt;@yashilmohadawoo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;as per my understanding , you want to reset your Splunk web login password, if yes, please follow below&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;rename the file /opt/splunk/etc/passwd to passwd_old&lt;BR /&gt;crete the new file user-seed.conf in /opt/splunk/etc/system/local/user-seed.conf&lt;BR /&gt;add following contents&lt;BR /&gt;[user_info]&lt;BR /&gt;USERNAME = admin&lt;BR /&gt;PASSWORD = &amp;lt;your cutstom password&amp;gt;&lt;/P&gt;&lt;P&gt;restart the splunk,&lt;/P&gt;&lt;P&gt;now you can able to login on Splunk UI&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 04:42:04 GMT</pubDate>
    <dc:creator>SanjayReddy</dc:creator>
    <dc:date>2023-01-23T04:42:04Z</dc:date>
    <item>
      <title>Having trouble resetting a server enterprise password from linux?</title>
      <link>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627924#M16546</link>
      <description>&lt;P&gt;Hey everyone, just wanted to get some help with regards to some issues i am facing with resetting a Server Enterprise Password from Linux,&amp;nbsp; i tried making a change onto the server.conf , from the local directory, specifically ,&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"/opt/splunk/etc/system/local" ..server.conf&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;Here is the current directory:&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;┌──(root㉿kali)-[/opt/splunk/etc/system/local]&lt;BR /&gt;└─# ls&lt;BR /&gt;deploymentclient.conf&amp;nbsp; &amp;nbsp;migration.conf&amp;nbsp; &amp;nbsp;README&amp;nbsp; &amp;nbsp;server.conf web.conf&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;{&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;[sslConfig]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;sslPassword =&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;[general]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;pass4SymmKey = &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;[lmpool:auto_generated_pool_download-trial]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;description = auto_generated_pool_download-trial&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;peers = *&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;quota = MAX&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;stack_id = download-trial&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;SPAN&gt;[lmpool:auto_generated_pool_forwarder]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;description = auto_generated_pool_forwarder&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;peers = *&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;quota = MAX&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;stack_id = forwarder&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;SPAN&gt;[lmpool:auto_generated_pool_free]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;description = auto_generated_pool_free&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;peers = *&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;quota = MAX&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;stack_id = free&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;}&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;From the above, i have also tried removing the SHA 256 algorithm Hash key under the,&amp;nbsp; "&lt;SPAN&gt;pass4SymmKey =", as well as "sslPassword ="m but after restarting the server, these fields which i omitted, seem to be blank by now ..&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;As per some help, i was able to remove and also delete the, the server.conf, and prior to that i stopped the server with the following command&amp;nbsp; ...&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$ ./splunk stop&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Then after, this i tried restarting the server with the following command , but the issue here it is&amp;nbsp; not prompting me to create a new credentials, as per this page below :&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;┌──(root㉿kali)-[/opt/splunk/bin]&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;└─# ./splunk start&lt;BR /&gt;{&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Splunk&amp;gt; All batbelt. No tights.&lt;BR /&gt;&lt;BR /&gt;Checking prerequisites...&lt;BR /&gt;Checking http port [8000]: open&lt;BR /&gt;Checking mgmt port [8080]: open&lt;BR /&gt;Checking appserver port [127.0.0.1:8065]: open&lt;BR /&gt;Checking kvstore port [8191]: open&lt;BR /&gt;Checking configuration... Done.&lt;BR /&gt;Checking critical directories... Done&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;Checking kvstore port [8191]: open [223/1590]&lt;BR /&gt;Checking configuration... Done.&lt;BR /&gt;Checking critical directories... Done&lt;BR /&gt;Checking indexes...&lt;BR /&gt;Validated: _audit _configtracker _internal _introspection _metrics _metrics_rollup _telemetry _thefishbucket history main summary&lt;BR /&gt;Done&lt;BR /&gt;Checking filesystem compatibility... Done&lt;BR /&gt;Checking conf files for problems...&lt;BR /&gt;Invalid key in stanza [instrumentation.usage.tlsBestPractices] in /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf, line 451: | append [| rest /services/configs/conf-pythonSslClientConfig | eval ssl&lt;BR /&gt;VerifyServerCert (value: if(isnull(sslVerifyServerCert),"unset",sslVerifyServerCert), splunk_server=sha256(splunk_server) | stats values(eai:acl.app) as python_configuredApp values(sslVerifyServerCert) as python_sslVerifyServerCert by s&lt;BR /&gt;plunk_server | eval python_configuredSystem=if(python_configuredApp="system","true","false") | fields python_sslVerifyServerCert, splunk_server, python_configuredSystem]&lt;BR /&gt;| append [| rest /services/configs/conf-web/settings | eval mgmtHostPort=if(isnull(mgmtHostPort),"unset",mgmtHostPort), splunk_server=sha256(splunk_server) | stats values(eai:acl.app) as fwdrMgmtHostPort_configuredApp values(mgmtHostPor&lt;BR /&gt;t) as fwdr_mgmtHostPort by splunk_server | eval fwdrMgmtHostPort_configuredSystem=if(fwdrMgmtHostPort_configuredApp="system","true","false") | fields fwdrMgmtHostPort_sslVerifyServerCert, splunk_server, fwdrMgmtHostPort_configuredSystem&lt;BR /&gt;]&lt;BR /&gt;| append [| rest /services/configs/conf-server/sslConfig | eval cliVerifyServerName=if(isnull(cliVerifyServerName),"feature",cliVerifyServerName), splunk_server=sha256(splunk_server) | stats values(cliVerifyServerName) as servername_cli&lt;BR /&gt;VerifyServerName values(eai:acl.app) as servername_configuredApp by splunk_server | eval cli_configuredSystem=if(cli_configuredApp="system","true","false") | fields cli_sslVerifyServerCert, splunk_server, cli_configuredSystem]&lt;BR /&gt;| stats values(*) as * by splunk_server | eval date=now() | makejson output=data | eval _time=date, date=strftime(date,"%Y-%m-%d") | fields data date _time).&lt;BR /&gt;Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'&lt;BR /&gt;Done&lt;BR /&gt;Checking default conf files for edits...&lt;BR /&gt;Validating installed files against hashes from '/opt/splunk/splunk-9.0.3-dd0128b1f8cd-linux-2.6-x86_64-manifest'&lt;BR /&gt;All installed files intact.&lt;BR /&gt;Done&lt;BR /&gt;All preliminary checks passed.&lt;/P&gt;
&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;PYTHONHTTPSVERIFY is set to 0 in splunk-launch.conf disabling certificate validation for the httplib and urllib libraries shipped with the embedded Python interpreter; must be set to "1" for increased security&lt;BR /&gt;Enter PEM pass phrase:&lt;BR /&gt;Done&lt;/P&gt;
&lt;P&gt;}&lt;/P&gt;
&lt;P&gt;Waiting for web server at &lt;A href="http://127.0.0.1:webport" target="_blank" rel="noopener"&gt;http://127.0.0.1:webport&lt;/A&gt;&amp;nbsp;to be available.................................................... Done&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If you get stuck, we're here to help.&lt;BR /&gt;Look for answers here: &lt;A href="http://docs.splunk.com" target="_blank" rel="noopener"&gt;http://docs.splunk.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The Splunk web interface is at &lt;A href="http://kali:8000" target="_blank" rel="noopener"&gt;http://kali::webport &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone help me to change the password, concurrently, i have both "Splunk forwarder" installed on the both machine , Windows Host as well as the&amp;nbsp; Linux Machine.. But i will like to ingest data from my Linux Machine , this happened recently until i forgot the Server Enterprise password under the VMNET 1, Linux Machine,&amp;nbsp; ,192.168.0.0/24 :the {&lt;A href="http://ocalhost,:web" target="_blank" rel="noopener"&gt;http://ocalhost,:web&lt;/A&gt; port }, Windows is working fine at the local address 127.0.0.1:webport ..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for all the help in advance ..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Jan 2023 19:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627924#M16546</guid>
      <dc:creator>yashilmohadawoo</dc:creator>
      <dc:date>2023-01-23T19:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Login reset Spl</title>
      <link>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627931#M16547</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253141"&gt;@yashilmohadawoo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;as per my understanding , you want to reset your Splunk web login password, if yes, please follow below&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;rename the file /opt/splunk/etc/passwd to passwd_old&lt;BR /&gt;crete the new file user-seed.conf in /opt/splunk/etc/system/local/user-seed.conf&lt;BR /&gt;add following contents&lt;BR /&gt;[user_info]&lt;BR /&gt;USERNAME = admin&lt;BR /&gt;PASSWORD = &amp;lt;your cutstom password&amp;gt;&lt;/P&gt;&lt;P&gt;restart the splunk,&lt;/P&gt;&lt;P&gt;now you can able to login on Splunk UI&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 04:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627931#M16547</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2023-01-23T04:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Login reset Spl</title>
      <link>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627945#M16548</link>
      <description>&lt;P&gt;Sir can you also help me with resetting my password, for the Splunk Server, enterprise through the&amp;nbsp; 127.0.0.1, currently on my windows machine, i have been locked out, i can only log into the splunk instance cloud, but not the server enterprise on the localhost:80....Webport&lt;/P&gt;&lt;P&gt;At the same time i wanted to ask you if in case the server.conf , through the directory, /opt/splunk/etc//local/system ..&amp;nbsp; if currently nothing&amp;nbsp; on the ssl password as well as the&amp;nbsp; passkey, would be an issue as when restarted&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;{&lt;/P&gt;&lt;P&gt;sslConfig]&lt;BR /&gt;sslPassword =&lt;BR /&gt;[general]&lt;BR /&gt;pass4SymmKey =&lt;BR /&gt;[lmpool:auto_generated_pool_download-trial]&lt;BR /&gt;description = auto_generated_pool_download-trial&lt;BR /&gt;peers = *&lt;BR /&gt;quota = MAX&lt;BR /&gt;stack_id = download-trial&lt;/P&gt;&lt;P&gt;[lmpool:auto_generated_pool_forwarder]&lt;BR /&gt;description = auto_generated_pool_forwarder&lt;BR /&gt;peers = *&lt;BR /&gt;quota = MAX&lt;BR /&gt;stack_id = forwarder&lt;/P&gt;&lt;P&gt;[lmpool:auto_generated_pool_free]&lt;BR /&gt;description = auto_generated_pool_free&lt;BR /&gt;peers = *&lt;BR /&gt;quota = MAX&lt;BR /&gt;stack_id = free&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;I am not sure if that is correct as i have a long string process, with the algorithm type , can you help me to identify some of which if ever may be causing an issue.. It is outside of my comprehension why is there so many processes&amp;nbsp; under Splunk on my linux ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;┌──(kali㉿kali)-[~]&lt;BR /&gt;└─$ ps -eF | grep splunk splunk 1117 1 0 91071 103088 0 00:17 ? 00:00:36 splunkd --under-systemd --systemd-delegate=yes -p 8089 _int&lt;BR /&gt;ernal_launch_under_systemd splunk 1313 1117 0 29684 5712 2 00:18 ? 00:00:00 [splunkd pid=1117] splunkd --under-systemd --systemd-delegate=yes -p 8089 _internal_launch_under_systemd [process-runner] root 75854 1 0 18793 64132 2 02:38 ? 00:00:01 /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py root 80622 1 8 85198 147372 1 02:47 ? 00:00:01 splunkd -p 8080 restart root 80623 80622 0 29684 19284 0 02:47 ? 00:00:00 [splunkd pid=80622] splunkd -p 8080 restart [process-runner]&lt;BR /&gt;root 80803 80623 2 20967 41140 0 02:47 ? 00:00:00 mongod --dbpath=/opt/splunk/var/lib/splunk/kvstore/mongo --&lt;BR /&gt;storageEngine=wiredTiger --wiredTigerCacheSizeGB=0.256000 --port=8191 --timeStampFormat=iso8601-utc --oplogSize=200 --keyFile=/&lt;BR /&gt;opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key --setParameter=enableLocalhostAuthBypass=0 --setParameter=oplogFetcherSteady&lt;BR /&gt;StateMaxFetcherRestarts=0 --replSet=EA7B7BD0-0109-429F-A25E-68B3C7528516 --bind_ip=0.0.0.0 --sslMode=requireSSL --sslAllowInval&lt;BR /&gt;idHostnames --sslPEMKeyFile=/opt/splunk/etc/auth/server.pem --tlsDisabledProtocols=noTLS1_0,noTLS1_1 --sslCipherConfig=ECDHE-EC&lt;BR /&gt;DSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-&lt;BR /&gt;SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128&lt;BR /&gt;-GCM-SHA256:ECDH-ECDSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256 --nounixsocket --noscripting&lt;BR /&gt;kali 80901 80726 0 1583 2076 2 02:47 pts/5 00:00:00 grep --color=auto splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me to eliminate any of these many processes, cause i see a lot of the pythonpath, initiating the&amp;nbsp;instance_id_modular_input.py, is this normal ..?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run the following command :&lt;/P&gt;&lt;P&gt;From the kali machine :&lt;/P&gt;&lt;P&gt;dir : "/opt/splunk/bin/"&lt;/P&gt;&lt;P&gt;$ ./splunk stop&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ ./splunk start&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here i am being asked the a PEM Passphrase, can this be anything&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627945#M16548</guid>
      <dc:creator>yashilmohadawoo</dc:creator>
      <dc:date>2023-01-23T08:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Login reset Spl</title>
      <link>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627946#M16549</link>
      <description>&lt;P&gt;Thanks a lot for your support.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:23:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Having-trouble-resetting-a-server-enterprise-password-from-linux/m-p/627946#M16549</guid>
      <dc:creator>yashilmohadawoo</dc:creator>
      <dc:date>2023-01-23T08:23:48Z</dc:date>
    </item>
  </channel>
</rss>

