Getting Data In

How can I change the password without knowing the default or entered password for the forwarder?

shawno
New Member

/opt/splunkforwarder/bin/splunk edit user admin -password $NEWPASSWORD

This doesn't work - how can I change the password without knowing the default or entered password for the forwarder?

0 Karma

cmoyanof
New Member

Hello,

May be will be useful for you to copy the bold text below into another admin user with a known password /opt/splunkforwarder/etc/passwd

:admin:$6$zGmwWFy17AEdVhjN$9YkUUBa4LM.Eds96Qs.DtjPOjorXVT57dasdasdasdaca.hxJ75.mmsrYNLmSXcVqu3gHbdBRJXtXv/ceBm1::Administrator:admin:changeme@example.com:::32533

Restart Splunk. After the restart you should be able to login using the previous splunkforwarder

0 Karma

ansif
Motivator

Try below steps:

  • Move the $SPLUNK_HOME/etc/passwd file
    to $SPLUNK_HOME/etc/passwd.bak

  • Restart Splunk. After the restart you
    should be able to login using the
    default login (admin/changeme).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...