Splunk Search

What is the root user or splunk user's password for the Splunk 6.4 AMI? Not the Splunk Web UI, but the OS password.

jtsplunk
Splunk Employee
Splunk Employee

What is the root user or splunk user's password for the Splunk 6.4 AMI? Not the Splunk Web UI, but the OS password.

I need to adjust some iptables and firewall settings which require admin access.

This is not Splunk Cloud, but BYOL Splunk AMI.

Tags (2)
0 Karma
1 Solution

jdunlea
Contributor

It turns out that once you are logged onto the CLI using the ec2-user that you can change to the "root" or "splunk" user by doing one of the following:

$ sudo su - splunk

OR

$ sudo su - root

View solution in original post

0 Karma

jdunlea
Contributor

It turns out that once you are logged onto the CLI using the ec2-user that you can change to the "root" or "splunk" user by doing one of the following:

$ sudo su - splunk

OR

$ sudo su - root

0 Karma

ChrisG
Splunk Employee
Splunk Employee

username: admin
password: instance id from management console

See About the Splunk Enterprise AMI in the Splunk Enterprise Admin Manual and the Usage instructions on the AWS marketplace page.

0 Karma

Shack
Explorer

I downvoted this post because these are the Splunk Web credentials; not the credentials for ssh access.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

I asked one of the engineers about this, he said:

When launching an AMI from the marketplace, the user will pick their own ssh keys for access to the instance, usually using the 'ubuntu' user. I doubt the 'splunk' user has any keys setup for SSH access, but a customer could set them up themselves. There is probably no password, it just uses SSH key for auth.

0 Karma

Shack
Explorer

I downvoted this post because these are the Splunk Web credentials; not the credentials for ssh access.

0 Karma

jdunlea
Contributor

That is the password for the UI - I am also looking for the password for the "splunk" user on the OS itself in the Splunk AMI.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...