<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prompt for Splunk user when configuring Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60441#M11985</link>
    <description>&lt;P&gt;By default, the user there is admin/changeme, unless you've changed it.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2011 07:50:17 GMT</pubDate>
    <dc:creator>Stephen_Sorkin</dc:creator>
    <dc:date>2011-03-16T07:50:17Z</dc:date>
    <item>
      <title>Prompt for Splunk user when configuring Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60440#M11984</link>
      <description>&lt;P&gt;I've just upgraded to Splunk 4.2 and have installed and started the UF on a Linux box. But when I try to run,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk add forward-server &amp;lt;myip&amp;gt;:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I get prompted for a Splunk username and password. I've tried my Splunk indexer username (trial version at the moment) and local user credentials, but am obviously missing the point. Do I need to create a Splunk user (./splunk add user ...) on this machine first? If so, does this need to match a local user that the daemon will use?&lt;/P&gt;

&lt;P&gt;I have installed the Win32 UF to send to my indexer and that's working fine.&lt;/P&gt;

&lt;P&gt;Seems like this should be obvious (and I'm feeling dumb) but I can't find anything in the Docs. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2011 07:45:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60440#M11984</guid>
      <dc:creator>Mike_McMurray</dc:creator>
      <dc:date>2011-03-16T07:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Prompt for Splunk user when configuring Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60441#M11985</link>
      <description>&lt;P&gt;By default, the user there is admin/changeme, unless you've changed it.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2011 07:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60441#M11985</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2011-03-16T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Prompt for Splunk user when configuring Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60442#M11986</link>
      <description>&lt;P&gt;Ahh crap. My line of thinking was that this was prompting for credentials of the remote indexer and NOT the local splunk UF.&lt;BR /&gt;
So, yes, the UF config is asking for the credentials of the local splunk install, which was the default.&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2011 07:58:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60442#M11986</guid>
      <dc:creator>Mike_McMurray</dc:creator>
      <dc:date>2011-03-16T07:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Prompt for Splunk user when configuring Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60443#M11987</link>
      <description>&lt;P&gt;Change the password while you are at it:&lt;/P&gt;

&lt;P&gt;./splunk edit user admin -password coolNewP455w3rdddd&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2011 12:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Prompt-for-Splunk-user-when-configuring-Universal-Forwarder/m-p/60443#M11987</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-03-16T12:50:05Z</dc:date>
    </item>
  </channel>
</rss>

