Security

Unable to login splunk enterprise!

60795761
New Member

Hi Team,

i have restarted the Splunk server and i tried to login again with same user name and password. could not able to login ..even i have tried with new user name and password with same result.

i have un installed the splunk enterprise and given user password but i am getting error message saying like "Login failed"

can somebody help me on this.

Thanks,
Venkat

Tags (1)
0 Karma

nickhills
Ultra Champion

If you restore config files from $SPLUNK_HOME/etc over the top of a fresh installation you need to be mindful of a few things.

$SPLUNK_HOME/etc/auth/splunk.secret needs to be restored to the correct location before you start Splunk for the first time.
$SPLUNK_HOME/etc/passwd needs to be restored to enable any local users (admin)

If you didn't replace both of these files with the original version before you started Splunk you are in a pickle.
The issue you now have is that all of the encrypted passwords in all the config files will be unreadable.

Best approach (assuming you have backups of the two files above) is to wipe/reinstall making sure those files are there first.

If you do not have those files (or otherwise cant take this approach).
Stop Splunk
Delete $SPLUNK_HOME/etc/passwd (any local splunk users on that box will loose their passwords)
Start Splunk - this should prompt you to set a password for admin (or use the user-seed.conf approach https://docs.splunk.com/Documentation/Splunk/8.0.1/Admin/User-seedconf)

Confirm you can login as admin.
Have any local users reset their passwords - admin will have to supervise.
Replace any encrypted passwords in .conf files with Plaintext passwords and restart Splunk to have it re-encrypt them with the new secret.
Confirm any passwords or keys for external auth (SAML/LDAP/MFA) are replaced.

If my comment helps, please give it a thumbs up!

nickhills
Ultra Champion

how did you perform the restore?
did you install splunk, and then copy configs back in?

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...