Security

Splunk Enterprise Login

dannyze
Explorer

Hello all,

I am having problems logging into Enterprise. I've tried my username and password, admin and changeme after moving the opt/splunk/etc/ passwd file and renaming it. Still won't work. If there's any better way to reset to allow login, i'd appreciate it. It was working just fine yesterday.

Thank You

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Did you rename the right passwd file? Is Splunk installed somewhere else?

If you delete or rename the splunk_home/etc/passwd file and restart, it makes the admin password changeme everytime.

The only explanation is if you didn't rename the right file or some symbolic link exists.

0 Karma

dannyze
Explorer

jkat54
I believe I renamed the right file. Renamed passwd to passwd.back, a new file was then generated passwd. Did the restart and it won't allow me access. What could the symbolic link be you mentioned?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Do you have another authentication method configured, such as SSO or SAML? If these are enabled, you need to disable them for the local passwords to be used.

0 Karma

jkat54
SplunkTrust
SplunkTrust

@esix is right. Do you have local authentication disabled?

/Applications/splunk/bin/splunk btool authentication list --debug

0 Karma

dannyze
Explorer

So once I get to the btool file in the bin, what would I need to do?

0 Karma

jkat54
SplunkTrust
SplunkTrust

That whole line is a command you can run to show what type of authentication you have setup. Post the outputp

0 Karma

dannyze
Explorer

Thank you, this was the output
authType = Splunk
passwordHashAlgorithm = SHA512-crypt
[cacheTiming]
getUserInfoTTL = 10s
getUsersTTL = 10s
userLoginTTL = 0
[secrets]
filename =
namespace = splunk

0 Karma

ddrillic
Ultra Champion

Google says - alt text

Did you restart splunk?

0 Karma

dannyze
Explorer

I did do ./splunk restart. No luck.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...