Security

remove passwd file from /etc but can't initial the password for splunk again, why?

haqi
New Member

1, delete the passwd with non-root account
2, splunk stop and splunk start again
3, try to login in web browser with initial account(admin, changeme) but failed,

what's the possible reason for that?

0 Karma

mayurr98
Super Champion

which version of Splunk are you using?

If you are using latest version of splunk i.e. 7.1 then follow this steps from the below link:
https://answers.splunk.com/answers/834/how-to-reset-the-admin-password.html

OR

To reset the admin password:

1)Stop splunk service

2)Move the $SPLUNK_HOME/etc/passwd file to $SPLUNK_HOME/etc/passwd.bak

3)Start Splunk.
After the restart you should be able to login using the default login (admin/changeme).
Let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...