<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS Splunk Enterprise new EC2 instance login help in Security</title>
    <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754199#M18528</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313560"&gt;@bt2025&lt;/a&gt;&amp;nbsp;You can reset your admin password&amp;nbsp;&lt;/P&gt;&lt;P&gt;Find the passwd file for your instance (/opt/splunk/etc/passwd) and rename it to passwd.bk&lt;/P&gt;&lt;P&gt;Create a file named &lt;STRONG&gt;user-seed.conf&lt;/STRONG&gt; in your /opt/splunk/etc/system/local/ directory.&lt;/P&gt;&lt;P&gt;In the file add the following text:&lt;/P&gt;&lt;P&gt;[user_info]&lt;BR /&gt;PASSWORD = NEW_PASSWORD&lt;/P&gt;&lt;P&gt;In the place of "NEW_PASSWORD" insert the password you would like to use.&lt;/P&gt;&lt;P&gt;Restart Splunk Enterprise and use the new password to log into your instance from Splunk Web.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Reset-admin-password-for-Splunk-Instance-via-REST-API" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/Reset-admin-password-for-Splunk-Instance-via-REST-API&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 12 Oct 2025 06:20:10 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-10-12T06:20:10Z</dc:date>
    <item>
      <title>AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754198#M18527</link>
      <description>&lt;P&gt;NEED HELP:&amp;nbsp;Not able to sign-in with default password&lt;/P&gt;&lt;P&gt;On 11OCT2025, I tried launching a &lt;STRONG&gt;brand&lt;/STRONG&gt; new Splunk Enterprise v10.0.1 &lt;STRONG&gt;from AMI into AWS EC2&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The ASK:&amp;nbsp;Is there a way for me to change the default password via SSH?&lt;/P&gt;&lt;P&gt;If my AWS EC instance ID = "i&lt;SPAN&gt;-1234567890abcdefg"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;On the Splunk web-console "&lt;A href="http://a.b.c.d:8000" target="_blank" rel="noopener"&gt;http://a.b.c.d:8000"&lt;/A&gt;&lt;/P&gt;&lt;P&gt;username=admin&lt;/P&gt;&lt;P&gt;Attempted these default passwords with NO success.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SPLUNK-1234567890abcdefg&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SPLUNK-i-1234567890abcdefg&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SPLUNK-$1234567890abcdefg$&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SPLUNK-$i-1234567890abcdefg$&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bt2025_0-1760249484721.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40526i0E9A0DDFE45065C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bt2025_0-1760249484721.png" alt="bt2025_0-1760249484721.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Oct 2025 06:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754198#M18527</guid>
      <dc:creator>bt2025</dc:creator>
      <dc:date>2025-10-12T06:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754199#M18528</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313560"&gt;@bt2025&lt;/a&gt;&amp;nbsp;You can reset your admin password&amp;nbsp;&lt;/P&gt;&lt;P&gt;Find the passwd file for your instance (/opt/splunk/etc/passwd) and rename it to passwd.bk&lt;/P&gt;&lt;P&gt;Create a file named &lt;STRONG&gt;user-seed.conf&lt;/STRONG&gt; in your /opt/splunk/etc/system/local/ directory.&lt;/P&gt;&lt;P&gt;In the file add the following text:&lt;/P&gt;&lt;P&gt;[user_info]&lt;BR /&gt;PASSWORD = NEW_PASSWORD&lt;/P&gt;&lt;P&gt;In the place of "NEW_PASSWORD" insert the password you would like to use.&lt;/P&gt;&lt;P&gt;Restart Splunk Enterprise and use the new password to log into your instance from Splunk Web.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Reset-admin-password-for-Splunk-Instance-via-REST-API" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/Reset-admin-password-for-Splunk-Instance-via-REST-API&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Oct 2025 06:20:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754199#M18528</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-10-12T06:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754201#M18529</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313560"&gt;@bt2025&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please follow the below steps to reset the Splunk login&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;Navigate to the Splunk configuration directory&lt;/P&gt;&lt;P&gt;&amp;lt;Splunk installation directory&amp;gt;/splunk/etc/&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Back up the existing password file&lt;/P&gt;&lt;P&gt;mv passwd passwd.backup&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;Go to the local system configuration folder&lt;/P&gt;&lt;P&gt;&amp;lt;Splunk installation directory&amp;gt;/splunk/etc/system/local/&lt;/P&gt;&lt;P&gt;4. Create a new file named user-seed.conf&lt;/P&gt;&lt;P&gt;Add the following contents inside the file (replace &amp;lt;newpassword&amp;gt; with your desired password):&lt;/P&gt;&lt;P&gt;[user_info]&lt;BR /&gt;USERNAME = admin&lt;BR /&gt;PASSWORD = &amp;lt;newpassword&amp;gt;&lt;/P&gt;&lt;P&gt;5.&amp;nbsp;Restart Splunk from the command line&lt;/P&gt;&lt;P&gt;&amp;lt;Splunk installation directory&amp;gt;/splunk/bin/splunk restart&lt;/P&gt;</description>
      <pubDate>Sun, 12 Oct 2025 09:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754201#M18529</guid>
      <dc:creator>thahir</dc:creator>
      <dc:date>2025-10-12T09:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754203#M18530</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313560"&gt;@bt2025&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other replies give info on how to reset the password, but to confirm what the password *should* be...&lt;/P&gt;&lt;P&gt;The password for the user 'admin' should be SPLUNK-&lt;SPAN&gt;i&lt;/SPAN&gt;&lt;SPAN&gt;-1234567890abcdefg&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However - the error you are getting "Server Error" is not the same as password incorrect failure. Please can you use the developer console in your browser to see what the full response to the login request is using the Network tab?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Sun, 12 Oct 2025 09:52:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754203#M18530</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-10-12T09:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754208#M18531</link>
      <description>&lt;P&gt;Thank you this workaround works!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 04:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754208#M18531</guid>
      <dc:creator>bt2025</dc:creator>
      <dc:date>2025-10-13T04:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754209#M18532</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you this workaround works!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 04:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754209#M18532</guid>
      <dc:creator>bt2025</dc:creator>
      <dc:date>2025-10-13T04:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Splunk Enterprise new EC2 instance login help</title>
      <link>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754210#M18533</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you so very much!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Firstly, for dispelling the default AWS EC2 default password format of &lt;EM&gt;SPLUNK-$instanceID$&lt;/EM&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Net, you are absolutely right that the "server error" was not due to an incorrect password login.&lt;/P&gt;&lt;P&gt;Just for background info for other community explorers: This EC2 was deployed in us-east-1 with c5.xlarge.&lt;/P&gt;&lt;P&gt;I took the path of the workarounds given by the other Splunk community contributor(s) but initially it did not work. Due time constraints (too late on Saturday night), I gave up for the night.&lt;/P&gt;&lt;P&gt;The next day (Sunday), I tried the workarounds again, BAM! Works!&lt;/P&gt;&lt;P&gt;Net-net, I reckoned there was a long delay between the EC2 instance is READY "3/3 checks passed" and when it was actually SplunkD ready.&lt;/P&gt;&lt;P&gt;Thus, if other community readers encounter the same problem, please let your (Splunk v10) EC2 instance sit and simmer for a while before pulling your hair out on why the default password does NOT work.&lt;/P&gt;&lt;P&gt;Again, cheers always and continue happy splunk'ing!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 05:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/AWS-Splunk-Enterprise-new-EC2-instance-login-help/m-p/754210#M18533</guid>
      <dc:creator>bt2025</dc:creator>
      <dc:date>2025-10-13T05:11:29Z</dc:date>
    </item>
  </channel>
</rss>

