Security

New Install - Default Credentials Invalid

m314219
Explorer

I installed Splunk Enterprise 6.5.3 on a new WS2012R2 Core VM. I completed the install, changed the services to use a gMSA account and setup relevant groups and GPO settings. I set the services to logon with the gMSA account and started Splunkd and opened http://splunk:8000.

After getting to the webpage, I attempted to login with 'admin' and 'changeme'. The login attempt failed and I tried it a few more times, to make sure it wasn't me. After that I tried IE, thinking that there could be an issue with Firefox, but the login failed there as well. I did some searching on the Internet and noted mentions of the /etc/passwd file within $splunk_home. I went to the /etc folder on my system and found that it does not have the passwd file.

Any ideas as to what the issue is? Is there a way I can change the password though the CLI? I ran splunk edit user admin -password changeme -role admin -auth admin:password and the command is sitting there without completing or erroring out.

0 Karma

woodcock
Esteemed Legend

To reset the admin password you will need to have access to the file system. Rename/move the $SPLUNK_HOME/etc/passwd and restart splunk and the passwd file will be recreated with one login as admin and PW changeme.

0 Karma

m314219
Explorer

The passwd file did not exist. I'm thinking something went wrong with the install, as a new install worked fine.

pradeepkumarg
Influencer

Did you manually check the splunkd.log for any clues ?

0 Karma

cfonmedig
New Member

I just installed and instance of Splunk on Windows and the default ID and PSSWD says invalid even after I rename the passwd file and restart splunk. When i start splunk it is showing the user id and password that i used to download the software.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...