<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Install - Default Credentials Invalid in Security</title>
    <link>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322141#M8317</link>
    <description>&lt;P&gt;Did you manually check the splunkd.log for any clues ?&lt;/P&gt;</description>
    <pubDate>Sun, 09 Apr 2017 05:25:40 GMT</pubDate>
    <dc:creator>pradeepkumarg</dc:creator>
    <dc:date>2017-04-09T05:25:40Z</dc:date>
    <item>
      <title>New Install - Default Credentials Invalid</title>
      <link>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322140#M8316</link>
      <description>&lt;P&gt;I installed Splunk Enterprise 6.5.3 on a new WS2012R2 Core VM. I completed the install, changed the services to use a gMSA account and setup relevant groups and GPO settings. I set the services to logon with the gMSA account and started Splunkd and opened &lt;A href="http://splunk:8000"&gt;http://splunk:8000&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;After getting to the webpage, I attempted to login with 'admin' and 'changeme'. The login attempt failed and I tried it a few more times, to make sure it wasn't me. After that I tried IE, thinking that there could be an issue with Firefox, but the login failed there as well. I did some searching on the Internet and noted mentions of the /etc/passwd file within $splunk_home. I went to the /etc folder on my system and found that it does not have the passwd file.&lt;/P&gt;

&lt;P&gt;Any ideas as to what the issue is? Is there a way I can change the password though the CLI? I ran splunk edit user admin -password changeme -role admin -auth admin:password and the command is sitting there without completing or erroring out.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2017 19:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322140#M8316</guid>
      <dc:creator>m314219</dc:creator>
      <dc:date>2017-04-08T19:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: New Install - Default Credentials Invalid</title>
      <link>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322141#M8317</link>
      <description>&lt;P&gt;Did you manually check the splunkd.log for any clues ?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Apr 2017 05:25:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322141#M8317</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2017-04-09T05:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: New Install - Default Credentials Invalid</title>
      <link>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322142#M8318</link>
      <description>&lt;P&gt;To reset the admin password you will need to have access to the file system.  Rename/move the &lt;CODE&gt;$SPLUNK_HOME/etc/passwd&lt;/CODE&gt; and restart splunk and the passwd file will be recreated with one login as &lt;CODE&gt;admin&lt;/CODE&gt; and PW &lt;CODE&gt;changeme&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Apr 2017 19:02:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322142#M8318</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-09T19:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: New Install - Default Credentials Invalid</title>
      <link>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322143#M8319</link>
      <description>&lt;P&gt;The passwd file did not exist. I'm thinking something went wrong with the install, as a new install worked fine.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jun 2017 14:43:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322143#M8319</guid>
      <dc:creator>m314219</dc:creator>
      <dc:date>2017-06-03T14:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: New Install - Default Credentials Invalid</title>
      <link>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322144#M8320</link>
      <description>&lt;P&gt;I just installed and instance of Splunk on Windows and the default ID and PSSWD says invalid even after I rename the passwd file and restart splunk. When i start splunk it is showing the user id and password that i used to download the software.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 13:54:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/New-Install-Default-Credentials-Invalid/m-p/322144#M8320</guid>
      <dc:creator>cfonmedig</dc:creator>
      <dc:date>2018-04-26T13:54:57Z</dc:date>
    </item>
  </channel>
</rss>

