I asked one of the engineers about this, he said:
When launching an AMI from the marketplace, the user will pick their own ssh keys for access to the instance, usually using the 'ubuntu' user. I doubt the 'splunk' user has any keys setup for SSH access, but a customer could set them up themselves. There is probably no password, it just uses SSH key for auth.
... View more