|
Answer» Depending on your Splunk version, you can RESET the Admin password. In case you have Splunk 7.1 and higher version, then you need to follow these steps: - Splunk Enterprise must be stopped first.
- Find and rename ‘passwd’ file to ‘passwd.bk’.
- In the below directory, CREATE a file NAMED 'user-seed.conf':
$SPLUNK_HOME/etc/system/local/- Enter the following command in the file. 'NEW_PASSWORD' will be replaced by our own NEW password here.
[user_info] PASSWORD = NEW_PASSWORD- Restart Splunk Enterprise and log in with the new password again.
If you're using a version prior to 7.1, you need to follow these steps: - Splunk Enterprise must be stopped first.
- Find and rename ‘passwd’ file to ‘passwd.bk’.
- Use the DEFAULT credentials of admin/changeme to log in to Splunk Enterprise.
- If you're asked to change your admin username and password, just follow the instructions.
|