<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change on prem universal forwarder credential in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581549#M102517</link>
    <description>&lt;P&gt;The forwarder's admin credentials have no bearing on its ability to forward data.&amp;nbsp; The credentials are used only in the user interface (CLI).&lt;/P&gt;&lt;P&gt;To change the password, first create a $SPLUNK_HOME/etc/system/local/user-seed.conf file on the forwarder.&amp;nbsp; The file should look like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[user_info]
USERNAME = admin
PASSWORD = somepassword&lt;/LI-CODE&gt;&lt;P&gt;Then delete $SPLUNK_HOME/etc/passwd and restart the forwarder.&amp;nbsp; When the forwarder starts up it will populate a new passwd file using the contents of user-seed.conf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jan 2022 20:19:51 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-01-18T20:19:51Z</dc:date>
    <item>
      <title>Change on prem universal forwarder credential</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581492#M102511</link>
      <description>&lt;P&gt;We have several servers succesfully forwarding eventlogs to our on prem splunk server. No one can remember the credentials when installing the forwarder. What is the best way to handle this problem without breaking forwarding on the other servers?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 16:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581492#M102511</guid>
      <dc:creator>dkordyban</dc:creator>
      <dc:date>2022-01-18T16:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Change on prem universal forwarder credential</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581504#M102513</link>
      <description>&lt;P&gt;If you are saying that you set an admin password during installation you can change it %splunk_home %\etc\passwd rename it passed.bak and restart splunk it will create a new file default passed is I think changeme.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 16:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581504#M102513</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-18T16:50:49Z</dc:date>
    </item>
    <item>
      <title>Change on prem universal forwarder credential</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581549#M102517</link>
      <description>&lt;P&gt;The forwarder's admin credentials have no bearing on its ability to forward data.&amp;nbsp; The credentials are used only in the user interface (CLI).&lt;/P&gt;&lt;P&gt;To change the password, first create a $SPLUNK_HOME/etc/system/local/user-seed.conf file on the forwarder.&amp;nbsp; The file should look like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[user_info]
USERNAME = admin
PASSWORD = somepassword&lt;/LI-CODE&gt;&lt;P&gt;Then delete $SPLUNK_HOME/etc/passwd and restart the forwarder.&amp;nbsp; When the forwarder starts up it will populate a new passwd file using the contents of user-seed.conf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 20:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581549#M102517</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-18T20:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Change on prem universal forwarder credential</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581552#M102518</link>
      <description>&lt;P&gt;This method hasn't been supported since an early 7.x release.&amp;nbsp; Splunk does not have a default password any longer.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 20:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-on-prem-universal-forwarder-credential/m-p/581552#M102518</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-01-18T20:26:48Z</dc:date>
    </item>
  </channel>
</rss>

