Security
Highlighted

Interesting... passwd file over rules user-seed.conf

Builder

Not sure if this has been seen by others and it didn't turn up in my searches...

I have a 7.3.3 instance where I forgot the admin password. So I created a $SPLUNK_HOME/etc/system/local/user-seed.conf, restarted, but I couldn't log in with the password. Additionally, the user-seed.conf file was still present.

Turns out there was still a $SPLUNKHOME/etc/passwd file (presumably from previous upgrades). I moved that to the $SPLUNKHOME/etc/passwd.bak, restarted and then Splunk used the user-seed.conf file to reset the admin password.

Hope this helps someone else...

Highlighted

Re: Interesting... passwd file over rules user-seed.conf

Builder

More of a statement above than a question..

View solution in original post

0 Karma