Getting Data In

Cannot Login to Forwarder

pchukwuma
New Member

After installing the Forwarder, I cannot login to it. I have executed SPLUNK CLEAN ALL, but cannot login. I also tried placing the user-seed.conf in the etc/system/local directory, but I still cannot login. What am I missing?

Tags (2)
0 Karma

Paolo_Prigione
Builder

Was the admin's default password of "changeme" ever changed? If you can not figure out the password, then

  1. stop the UF
  2. rename the $SPLUNK_HOME/etc/passwd file

Now you have the default credentials (admin/changeme) back.

However, if you want to achieve similar results to clean all, then:

  1. stop the UF
  2. rename $SPLUNK_HOME/var to something else
  3. rename $SPLUNK_HOME/etc/users to something else
  4. start the UF
  5. if everything works fine, drop the renamed folders.

Ayn
Legend

How are you trying to login? What credentials are you using?

0 Karma

DaveSavage
Builder

When you say 'log in' you are trying to connect to it through the GUI? It doesn't support that. You can access it via the CLI and there is a rich thread on the commands at http://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands (thanks Drainy 😉

0 Karma

pchukwuma
New Member

I am trying to login through the CLI. The Splunk Clean All is a CLI command.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...