Splunk Enterprise

user-seed.conf not working

mikelanghorst
Motivator

I'm attempting to use the user-seed.conf to set the admin password for my Windows Universal Forwarder installations, but not having any luck with it.

My installation command:
msiexec /i splunkforwarder-4.3.1-119532-x86-release.msi SPLUNKD_PORT=9998 DEPLOYMENT_SERVER=xxx.xxx.xxx.xxx:8089 LAUNCHSPLUNK=1 /quiet

I then replaced the $splunk_home\etc\system\default\user-seed.conf and started splunk using the Service Menu. I'm then only able to login using admin:changeme

Tags (1)
1 Solution

amrit
Splunk Employee
Splunk Employee

I think this has to be done before the very first start. Maybe you want install the MSI with /LAUNCHSPLUNK=0 and create user-seed.conf, then start the Splunk service?

View solution in original post

amrit
Splunk Employee
Splunk Employee

I think this has to be done before the very first start. Maybe you want install the MSI with /LAUNCHSPLUNK=0 and create user-seed.conf, then start the Splunk service?

mikelanghorst
Motivator

I had LAUNCHSPLUNK=0 originally, expecting that it wouldn't start the first time. So it appears that the UF runs the first time no matter what. I had seen something in the docs that suggested so, but wanted to get confirmation before I add the additional commands to change the password. Maybe user-seed.conf only works for *nix installations?

0 Karma

mikelanghorst
Motivator

From the initial installation it looks to have read this file:
04-24-2012 16:20:52.722 -0700 WARN AuthenticationManagerSplunk - Failed to remove file 'C:\Program Files\SplunkUniversalForwarder\etc\system\default\user-seed.conf' errno=Access is denied.

There are no log messages for user-seed.conf on the subsequent start.
Does this file have to be placed before the installation occurs? I would expect that the installation would overwrite the file.

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...