Security

After launching an AWS instance for Splunk Enterprise AMI, what is the default username/password to access Splunk Web?

dzlabs
Engager

I've launched an AWS instance for the Splunk Enterprise AMI (https://aws.amazon.com/marketplace/pp/B00PUXWXNE ) with a public address. When I open http://pubic_address:8000/ on the browser, I cannot log in with user 'admin' and password 'changeme'. What are the default username/password to use?

0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

I think the user name is still admin, but the password is the instance ID.

View solution in original post

ebundschuh_splu
Splunk Employee
Splunk Employee

As of version 7.2.5 the default password has been updated

username: admin
password: SPLUNK-$instance id$

https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/AbouttheSplunkAMI

ChrisG
Splunk Employee
Splunk Employee

I think the user name is still admin, but the password is the instance ID.

tsullivan06
Explorer

This answer is only for instance up to v7.2.5 - after v7.2.5 the password is SPLUNK-instance ID 

per the docs: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/AbouttheSplunkAMI :

  • For Splunk version 7.2.5 and above, log into Splunk Enterprise with the credentials:
    • username: admin
    • password: SPLUNK-$instance id$
    • It is recommended that you change your password after login.
  • For Splunk version below 7.2.5, log into Splunk Enterprise with the credentials:
    • username: admin
    • password: $instance id$
    • On the next screen, set a new password.
0 Karma

sduchene_splunk
Splunk Employee
Splunk Employee

please modify the answer : today the password is SPLUNK-{instanceID} as described in AWS marketplace, usage page

bpitts2
Path Finder

Usage Instructions


Get started with Splunk Web:

  • In your EC2 Management Console, find your instance running Splunk Enterprise.
  • Copy its public IP.
  • Paste the public IP into a new browser tab (do not hit enter yet).
  • Append :8000 to the end of the IP.
  • Hit enter.

  • Log into Splunk with the following credentials:

username: admin
password: {the instance id of the instance just created}

0 Karma

bpitts2
Path Finder

The link that you posted is 404'ing

0 Karma

bpitts2
Path Finder

Looks like you're just missing an 'E' at the end of the URL

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...