Splunk's $SPLUNK_HOME/etc/passwd File syntax and encryption/hashing algorithm


I've searched around a good bit.. haven't found any official documentation on the topic.

On Splunk forwarders and indexers, Splunk stores users and their info in $SPLUNK_HOME/etc/passwd

Cat-ing the file on one of my forwarders looks like this:


My two questions are:

  1. What is the full syntax for the passwd file? Some fields are obvious, but I still haven't found any offical docs on the syntax.
  2. How is the hashed password generated? Is it actually a hash, or a reversible encryption? In either case, what algorithm is used and how is it seeded?

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>