Getting Data In

Enable forward-server in Linux Universal Forwarder

frejen
New Member

Hi,

I have some problems with running the following command.

$ splunk add forward-server host:port

It asks for username and password, i assume that the credentials should be the ones used when logging in to the Splunk WebUI. But authentication fails. I have also tried with the credentials for the local Splunk account. But still no luck.

When reading the Universal Deployment Manual I can not see any information about authentication. I have not added any SSL Cert, i guess this issue can be related to SSL communication between Forwarder and Reciever. But i just want to use the default certs.

I have tried running the command both as root and splunk user. But no luck at all.

Any ideas?

0 Karma
1 Solution

sergemueller
Explorer

there is a small hint in the universalforwader docu.(i think its a comment)

it is the default login:
admin/changeme

View solution in original post

unwiresplunk
New Member

Thank you lukejadamec, that was outside my thinking box at the time of writing - the file is like a htpasswd file... I should have noticed that 🙂 Thanks

0 Karma

lukejadamec
Super Champion

Yes, there is a way to change the password without using the -password parameter.

See this article from Splunk:
docs.splunk.com/Documentation/Splunk/5.0.3/Security/Deploysecurepasswordsacrossmultipleservers

0 Karma

unwiresplunk
New Member

Is there a way to change the password without using the "-password " parameter on the CLI to avoid using a script to keep .bash_history clean ?

0 Karma

sergemueller
Explorer

there is a small hint in the universalforwader docu.(i think its a comment)

it is the default login:
admin/changeme

sergemueller
Explorer

http://splunk-base.splunk.com/answers/12638/prompt-for-splunk-user-when-configuring-universal-forwar...

search is your friend:)

./splunk edit user admin -password coolNewP455w3rdddd

0 Karma

frejen
New Member

Hi,

Thank you that did the trick! But the password for "admin" i use to login to WebUI has been changed is not "changeme". How can i change that password?

Frej

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...