Security

New forwarder: An Admin password is required???

dpapenbro
New Member

Running V7.1, but just Installed a new forwarder and received this response: This appears to be your first time running this version of Splunk. An Admin password must be set before installation proceeds. Password must contain at least: * 8 total printable ASCII character(s). Please enter a new password: Please confirm new password:; Is this a new feature? What password is being requested?

Tags (1)
0 Karma

xpac
SplunkTrust
SplunkTrust

From v7.1, Splunk requires you to set the admin password, because else people tend to stick with changeme 😉
You can put in whatever password you like, but make sure to remember it.

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

vvedanta
Loves-to-Learn Lots

when do we even use this forwarder admin/pass?

0 Karma

mikelanghorst
Motivator

On a forwarder it's rare that I've used it, other than checking the status of the tailingProcessor and such.

https://www.splunk.com/blog/2011/01/02/did-i-miss-christmas-2.html

0 Karma

vvedanta
Loves-to-Learn Lots

So its ok leave it to default in that case?

0 Karma

maciep
Champion

I would not leave it default...it may not be used often but it can be exploited for bad things. For example, somebody connecting to it with the default username/password, pointing it to a rogue deployment server, pushing down scripts to run in context of the splunk user and possibly owning the box.

On the UF's, we set a random password for the admin account and disable the management port.

Have a look at this .conf session from a couple years back:
https://conf.splunk.com/files/2016/recordings/universal-forwarder-security-dont-input-more-than-data...

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...