Hello, i'm trying to retrieve my lab's admin account but no success.
I tried the method of deleting the passwd file plus create user-seed.conf in system/local but didn't worked.
any ideas? Thanks!
The easiest way is to just to reset it by adding a user-seed.conf
, deleting the existing entry in $SPLUNK_HOME/etc/passwd
, then restarting splunk:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/User-seedconf
The easiest way is to just to reset it by adding a user-seed.conf
, deleting the existing entry in $SPLUNK_HOME/etc/passwd
, then restarting splunk:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/User-seedconf
Have you tried resetting the password hash? i haven't tested it in 8 but a good write-up on it is available here: https://www.hurricanelabs.com/splunk-tutorials/splunk-7-1-performing-a-splunk-password-reset
Sorry for the delay in my answer, the link goes 404 😞
Looks like the hyperlink added the period onto it and broke the link. I just removed the period from the link and it should work now.