Getting Data In

Enable forward-server in Linux Universal Forwarder

frejen
New Member

Hi,

I have some problems with running the following command.

$ splunk add forward-server host:port

It asks for username and password, i assume that the credentials should be the ones used when logging in to the Splunk WebUI. But authentication fails. I have also tried with the credentials for the local Splunk account. But still no luck.

When reading the Universal Deployment Manual I can not see any information about authentication. I have not added any SSL Cert, i guess this issue can be related to SSL communication between Forwarder and Reciever. But i just want to use the default certs.

I have tried running the command both as root and splunk user. But no luck at all.

Any ideas?

0 Karma
1 Solution

sergemueller
Explorer

there is a small hint in the universalforwader docu.(i think its a comment)

it is the default login:
admin/changeme

View solution in original post

unwiresplunk
New Member

Thank you lukejadamec, that was outside my thinking box at the time of writing - the file is like a htpasswd file... I should have noticed that 🙂 Thanks

0 Karma

lukejadamec
Super Champion

Yes, there is a way to change the password without using the -password parameter.

See this article from Splunk:
docs.splunk.com/Documentation/Splunk/5.0.3/Security/Deploysecurepasswordsacrossmultipleservers

0 Karma

unwiresplunk
New Member

Is there a way to change the password without using the "-password " parameter on the CLI to avoid using a script to keep .bash_history clean ?

0 Karma

sergemueller
Explorer

there is a small hint in the universalforwader docu.(i think its a comment)

it is the default login:
admin/changeme

sergemueller
Explorer

http://splunk-base.splunk.com/answers/12638/prompt-for-splunk-user-when-configuring-universal-forwar...

search is your friend:)

./splunk edit user admin -password coolNewP455w3rdddd

0 Karma

frejen
New Member

Hi,

Thank you that did the trick! But the password for "admin" i use to login to WebUI has been changed is not "changeme". How can i change that password?

Frej

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...