Security

Resetting Administrator Password on Free License

msharp_smcm
Engager

So I know that the standard way of doing this is listed here:
http://splunk-base.splunk.com/answers/834/how-could-i-reset-the-admin-password/836
However, what exactly does "move the $SPLUNK_HOME/etc/passwd file to passwd.bak" mean? Just a rename? Because if that's the case it's not working for me.
Thanks for any help!

Tags (2)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Usually deleting the $SPLUNK_HOME/etc/passwd and restarting reset it all.
But also once the expired trial license turns into a free license, then Splunk has no passwords whatsoever.

View solution in original post

christinmb
Path Finder

Did you restarted both services? I just followed all the steps in the link you gave and it worked.

0 Karma

yannK
Splunk Employee
Splunk Employee

Usually deleting the $SPLUNK_HOME/etc/passwd and restarting reset it all.
But also once the expired trial license turns into a free license, then Splunk has no passwords whatsoever.

msharp_smcm
Engager

Free licenses having no passwords is the answer then, thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...