Security

After launching an AWS instance for Splunk Enterprise AMI, what is the default username/password to access Splunk Web?

dzlabs
Engager

I've launched an AWS instance for the Splunk Enterprise AMI (https://aws.amazon.com/marketplace/pp/B00PUXWXNE ) with a public address. When I open http://pubic_address:8000/ on the browser, I cannot log in with user 'admin' and password 'changeme'. What are the default username/password to use?

0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

I think the user name is still admin, but the password is the instance ID.

View solution in original post

ebundschuh_splu
Splunk Employee
Splunk Employee

As of version 7.2.5 the default password has been updated

username: admin
password: SPLUNK-$instance id$

https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/AbouttheSplunkAMI

ChrisG
Splunk Employee
Splunk Employee

I think the user name is still admin, but the password is the instance ID.

tsullivan06
Explorer

This answer is only for instance up to v7.2.5 - after v7.2.5 the password is SPLUNK-instance ID 

per the docs: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/AbouttheSplunkAMI :

  • For Splunk version 7.2.5 and above, log into Splunk Enterprise with the credentials:
    • username: admin
    • password: SPLUNK-$instance id$
    • It is recommended that you change your password after login.
  • For Splunk version below 7.2.5, log into Splunk Enterprise with the credentials:
    • username: admin
    • password: $instance id$
    • On the next screen, set a new password.
0 Karma

sduchene_splunk
Splunk Employee
Splunk Employee

please modify the answer : today the password is SPLUNK-{instanceID} as described in AWS marketplace, usage page

bpitts2
Path Finder

Usage Instructions


Get started with Splunk Web:

  • In your EC2 Management Console, find your instance running Splunk Enterprise.
  • Copy its public IP.
  • Paste the public IP into a new browser tab (do not hit enter yet).
  • Append :8000 to the end of the IP.
  • Hit enter.

  • Log into Splunk with the following credentials:

username: admin
password: {the instance id of the instance just created}

0 Karma

bpitts2
Path Finder

The link that you posted is 404'ing

0 Karma

bpitts2
Path Finder

Looks like you're just missing an 'E' at the end of the URL

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...