Dashboards & Visualizations

Default Credentials on Splunk Trial License

prictoej
New Member

First time signing into my trial license and it says "If you installed this instance, use the username and password you created at installation". I did not create any credentials upon installation. I have uninstalled and reinstalled and receive the same prompt, is there a way to reset the credentials and log in? (v7.3.1.1 Windows)

0 Karma

woodcock
Esteemed Legend

Go to $SPLUNK_HOME/etc/passwd and look at what users are defined. Now you know the username. Try to login with that user and PW=changeme; it probably won't work. Grab the PW from that file and then use the method here to decrypt it and reveal the PW:
https://www.hurricanelabs.com/splunk-tutorials/make-splunk-do-it-how-to-decrypt-passwords-encrypted-...

There are other methods but this is the easiest one that does not require you to have an admin-level uers's login (this only requires CLI access; it does not require any splunk user).

0 Karma

codebuilder
SplunkTrust
SplunkTrust

As of version 7.1+ there is no default password ("changeme").

Also, the method for changing the password has changed. For your version, use the following steps:

Create a file in /op/splunk/etc/system/local/user-seed.conf (or Windows equivalent directory) and add the following parameters:

[user_info]
USERNAME = admin
PASSWORD = new_password_here

Then cycle Splunk and you should be good.

----
An upvote would be appreciated and Accept Solution if it helps!

JPrictoe
Loves-to-Learn

Thanks for the response. I think the previous comment was correct, it was installed in a directory I did not have full permissions on. I believe I have rectified that, I added a user-seed.conf file and put that stanza in, but Splunk still says "No users exist. Please set up a user".

0 Karma

codebuilder
SplunkTrust
SplunkTrust

When you created the userseed.conf file, did you make sure to change ownership to splunk?
If you're running Splunk as the splunk user, but the file is owned by root, Splunk will ignore it.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

ChrisG
Splunk Employee
Splunk Employee

Is it possible that you have installed it into a directory where you don't have full permissions? If so, perhaps the script to set the password can't run.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried admin/changeme?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...