@Bet1 -Stop Splunk Enterprise. -Find the passwd file for your instance ($SPLUNK_HOME/etc/passwd) and rename it to passwd.bk -Create a file named user-seed.conf in your $SPLUNK_HOME/etc/system/local/ directory. In the file add the following text: [user_info] USERNAME = admin PASSWORD = NEW_PASSWORD In the place of "NEW_PASSWORD" insert the password you would like to use. Start Splunk Enterprise and use the new password to log into your instance from Splunk Web. Regards, Prewin If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
... View more