Getting Data In

Cannot Login to Forwarder

pchukwuma
New Member

After installing the Forwarder, I cannot login to it. I have executed SPLUNK CLEAN ALL, but cannot login. I also tried placing the user-seed.conf in the etc/system/local directory, but I still cannot login. What am I missing?

Tags (2)
0 Karma

Paolo_Prigione
Builder

Was the admin's default password of "changeme" ever changed? If you can not figure out the password, then

  1. stop the UF
  2. rename the $SPLUNK_HOME/etc/passwd file

Now you have the default credentials (admin/changeme) back.

However, if you want to achieve similar results to clean all, then:

  1. stop the UF
  2. rename $SPLUNK_HOME/var to something else
  3. rename $SPLUNK_HOME/etc/users to something else
  4. start the UF
  5. if everything works fine, drop the renamed folders.

Ayn
Legend

How are you trying to login? What credentials are you using?

0 Karma

DaveSavage
Builder

When you say 'log in' you are trying to connect to it through the GUI? It doesn't support that. You can access it via the CLI and there is a rich thread on the commands at http://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands (thanks Drainy 😉

0 Karma

pchukwuma
New Member

I am trying to login through the CLI. The Splunk Clean All is a CLI command.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...