This answer is only for instance up to v7.2.5 - after v7.2.5 the password is SPLUNK-instance ID per the docs: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/AbouttheSplunkAMI : For Splunk version 7.2.5 and above, log into Splunk Enterprise with the credentials: username: admin password: SPLUNK-$instance id$ It is recommended that you change your password after login. For Splunk version below 7.2.5, log into Splunk Enterprise with the credentials: username: admin password: $instance id$ On the next screen, set a new password.
... View more