<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user-seed.conf not working in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34978#M8578</link>
    <description>&lt;P&gt;I think this has to be done before the very first start.  Maybe you want install the MSI with /LAUNCHSPLUNK=0 and create user-seed.conf, then start the Splunk service?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Apr 2012 00:41:20 GMT</pubDate>
    <dc:creator>amrit</dc:creator>
    <dc:date>2012-04-25T00:41:20Z</dc:date>
    <item>
      <title>user-seed.conf not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34976#M8576</link>
      <description>&lt;P&gt;I'm attempting to use the user-seed.conf to set the admin password for my Windows Universal Forwarder installations, but not having any luck with it.&lt;/P&gt;

&lt;P&gt;My installation command:&lt;BR /&gt;
msiexec /i splunkforwarder-4.3.1-119532-x86-release.msi SPLUNKD_PORT=9998 DEPLOYMENT_SERVER=xxx.xxx.xxx.xxx:8089 LAUNCHSPLUNK=1 /quiet&lt;/P&gt;

&lt;P&gt;I then replaced the $splunk_home\etc\system\default\user-seed.conf and started splunk using the Service Menu.  I'm then only able to login using admin:changeme&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34976#M8576</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34977#M8577</link>
      <description>&lt;P&gt;From the initial installation it looks to have read this file:&lt;BR /&gt;
04-24-2012 16:20:52.722 -0700 WARN  AuthenticationManagerSplunk - Failed to remove file 'C:\Program Files\SplunkUniversalForwarder\etc\system\default\user-seed.conf' errno=Access is denied.&lt;/P&gt;

&lt;P&gt;There are no log messages for user-seed.conf on the subsequent start.&lt;BR /&gt;
Does this file have to be placed before the installation occurs? I would expect that the installation would overwrite the file.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2012 00:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34977#M8577</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-04-25T00:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34978#M8578</link>
      <description>&lt;P&gt;I think this has to be done before the very first start.  Maybe you want install the MSI with /LAUNCHSPLUNK=0 and create user-seed.conf, then start the Splunk service?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2012 00:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34978#M8578</guid>
      <dc:creator>amrit</dc:creator>
      <dc:date>2012-04-25T00:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34979#M8579</link>
      <description>&lt;P&gt;I had LAUNCHSPLUNK=0 originally, expecting that it wouldn't start the first time.  So it appears that the UF runs the first time no matter what.  I had seen something in the docs that suggested so, but wanted to get confirmation before I add the additional commands to change the password.  Maybe user-seed.conf only works for *nix installations?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2012 01:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/user-seed-conf-not-working/m-p/34979#M8579</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-04-25T01:35:10Z</dc:date>
    </item>
  </channel>
</rss>

