Getting Data In

Questions about user-seed.conf

philip_wong
Communicator

I have few questions regarding to user-seed.conf
http://docs.splunk.com/Documentation/Splunk/latest/Admin/User-seedconf

  1. Is it only applied in first run? Or it will be taken after restart everytime?
  2. Only applied to "admin"
  3. The spec mentioned "Currently, only one user can be configured with user-seed.conf." Related to both 1 & 2, can I use it to create/change password for another user after restart?
Tags (1)
0 Karma

lguinn2
Legend

It is only applied on the first run - or if $SPLUNK_HOME/etc/passwd is missing.

You can put any user you want in it, at any time.

If the first-run password for admin is not set here, the first-run password for admin will be changeme.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...