Getting Data In

Enable forward-server in Linux Universal Forwarder

frejen
New Member

Hi,

I have some problems with running the following command.

$ splunk add forward-server host:port

It asks for username and password, i assume that the credentials should be the ones used when logging in to the Splunk WebUI. But authentication fails. I have also tried with the credentials for the local Splunk account. But still no luck.

When reading the Universal Deployment Manual I can not see any information about authentication. I have not added any SSL Cert, i guess this issue can be related to SSL communication between Forwarder and Reciever. But i just want to use the default certs.

I have tried running the command both as root and splunk user. But no luck at all.

Any ideas?

0 Karma
1 Solution

sergemueller
Explorer

there is a small hint in the universalforwader docu.(i think its a comment)

it is the default login:
admin/changeme

View solution in original post

unwiresplunk
New Member

Thank you lukejadamec, that was outside my thinking box at the time of writing - the file is like a htpasswd file... I should have noticed that 🙂 Thanks

0 Karma

lukejadamec
Super Champion

Yes, there is a way to change the password without using the -password parameter.

See this article from Splunk:
docs.splunk.com/Documentation/Splunk/5.0.3/Security/Deploysecurepasswordsacrossmultipleservers

0 Karma

unwiresplunk
New Member

Is there a way to change the password without using the "-password " parameter on the CLI to avoid using a script to keep .bash_history clean ?

0 Karma

sergemueller
Explorer

there is a small hint in the universalforwader docu.(i think its a comment)

it is the default login:
admin/changeme

sergemueller
Explorer

http://splunk-base.splunk.com/answers/12638/prompt-for-splunk-user-when-configuring-universal-forwar...

search is your friend:)

./splunk edit user admin -password coolNewP455w3rdddd

0 Karma

frejen
New Member

Hi,

Thank you that did the trick! But the password for "admin" i use to login to WebUI has been changed is not "changeme". How can i change that password?

Frej

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...