I've searched around a good bit.. haven't found any official documentation on the topic.
On Splunk forwarders and indexers, Splunk stores users and their info in $SPLUNK_HOME/etc/passwd
Cat-ing the file on one of my forwarders looks like this:
:admin:<hashed-password>::Administrator:admin:changeme@example.com:
My two questions are:
Hi i forgot my password, i need help in resetting it. many thanks