<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user-seed.conf not working in Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759797#M120384</link>
    <description>&lt;P&gt;This appears to be the resolution to my issue. Installing Splunk .v 10.2.1 with the 'LAUNCHSPLUNK=0 ' parameter still generates a passwd file during installation. Deleting the file before first start allows the user-seed.conf file to be read and deleted. Thanks to all for your help!&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2026 19:17:43 GMT</pubDate>
    <dc:creator>Stem</dc:creator>
    <dc:date>2026-03-30T19:17:43Z</dc:date>
    <item>
      <title>user-seed.conf not working in Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759747#M120380</link>
      <description>&lt;P&gt;I have installed the UF(.v 10.2.1) on a Windows server using the cli command below. Splunk appears to install successfully and the user.seed.conf is copied to&amp;nbsp;&lt;SPAN&gt;'C:\Program Files\SplunkUniversalForwarder\etc\system\local\user-seed.conf'. However, when I start Splunk the user-seed.conf file doesn't get deleted and any attempts to perform command line configurations result in 'Login Failed' errors. Any insight on what I'm missing/failing to do?&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Install Command:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;LI-CODE lang="markup"&gt;msiexec.exe /i C:\tmp\SplunkUniversalForwarder.msi AGREETOLICENSE=Yes LAUNCHSPLUNK=0 RECEIVING_INDEXER="192.168.10.10:9997" /qn&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 18:17:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759747#M120380</guid>
      <dc:creator>Stem</dc:creator>
      <dc:date>2026-03-27T18:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working in Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759749#M120381</link>
      <description>&lt;P&gt;Check the splunkd.log but generally that's happening if either splunkd cannot access the file or it has syntax errors.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 19:35:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759749#M120381</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-03-27T19:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working in Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759753#M120382</link>
      <description>Or you have already etc/passwd on place with content.</description>
      <pubDate>Fri, 27 Mar 2026 23:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759753#M120382</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2026-03-27T23:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working in Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759759#M120383</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/316419"&gt;@Stem&lt;/a&gt;&amp;nbsp;Most probably, the user-seed file is not being parsed, likely due to syntax, or permissions. You may review the Splunkd logs to figure out the issue.&lt;/P&gt;&lt;P&gt;Make sure to follow the below syntax for the user-seed.conf file. Any deviation (extra spaces, wrong section header) will cause Splunk to ignore it.&lt;/P&gt;&lt;P&gt;[user_info]&lt;BR /&gt;USERNAME = admin&lt;BR /&gt;PASSWORD = &amp;lt;yourpassword&amp;gt;&lt;/P&gt;&lt;P&gt;Confirm the Splunk service account has read access to the file. On Windows, run Splunk as Administrator during installation or startup.&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/9.4/configuration-file-reference/9.4.0-configuration-file-reference/user-seed.conf" target="_blank" rel="noopener"&gt;user-seed.conf | Platform (last updated 2026-01-13T21:03:58.807Z)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this post addressed your question, you can:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Give it&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;karma&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;to show appreciation&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Mark it as the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;solution&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if it solved your issue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Add a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;comment&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;if you’d like more details&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pencil:"&gt;✏️&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2026 18:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759759#M120383</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-03-28T18:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: user-seed.conf not working in Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759797#M120384</link>
      <description>&lt;P&gt;This appears to be the resolution to my issue. Installing Splunk .v 10.2.1 with the 'LAUNCHSPLUNK=0 ' parameter still generates a passwd file during installation. Deleting the file before first start allows the user-seed.conf file to be read and deleted. Thanks to all for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 19:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/user-seed-conf-not-working-in-Universal-Forwarder/m-p/759797#M120384</guid>
      <dc:creator>Stem</dc:creator>
      <dc:date>2026-03-30T19:17:43Z</dc:date>
    </item>
  </channel>
</rss>

