I am looking for a query that can help me list or audit systems that are using default passwords or any other method you think I can use to audit my environment for default passwords.
As soon as you can into splunk the data about passwords we can help you search it.
But you need to have that data. Splunk as such is "just" a data processing tool.
EDIT: Typically querying for default credentials is part of what vulnerability scanners do.