Security

Script for Splunk admin password change

inayath_khanin1
Explorer

Hi Folks, 

 

Can anyone please help me with a script that help to change splunk admin password across 100 servers? It should prompt what password to change with.

 

Thanks in advance 

Labels (1)
0 Karma
1 Solution

codebuilder
Influencer

You can use bash or python (amongst others) to create a script that incorporates the API or CLI examples  provided.

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

inayath_khanin1
Explorer

@codebuilder We are actually looking for a script that can be run one one server to change the password of rest servers. can u pls help us with this

0 Karma

codebuilder
Influencer

You can use bash or python (amongst others) to create a script that incorporates the API or CLI examples  provided.

----
An upvote would be appreciated and Accept Solution if it helps!

codebuilder
Influencer

If you want the user to be prompted you can do this via the CLI (obviously change your user name and admin password):

splunk edit user test_user -force-change-pass true -auth admin:changeme

Or via the API:

curl -k -u admin:changeme https://localhost:8089/services/authentication/users/test_user -d force-change-pass=true

Or if you want to set the new password outright:

splunk edit user <username> -auth admin:<admin_password> -password <password>

----
An upvote would be appreciated and Accept Solution if it helps!
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...