I am a Newbie and was having no trouble yesterday. Today, I booted up and it is as if either I forgot the password I entered or else the program is working with another entry.
How do you restart splunk?
On *nix:
$SPLUNK_HOME/bin/splunk restart
On windows:
$SPLUNK_HOME\bin\splunk.exe restart
For both $SPLUNK_HOME
is the path you installed Splunk.
cheers, MuS
Based on the advice of Iguinn and MuS, I went into the Splunk Folder using MAC's "Finder". Going into Apps/Splunk/, I went folder by folder to find the passwd document (located in /Splunk/etc). Then, I set up a folder called OLD and moved the PASSWD document into it.
At first, it appeared that this did not solve the problem, and then I realized it was necessary to restart.
I simply used the admin and changeme entries and was able to proceed.
Thanks so much for taking the time to help a beginner. I speaks well of the Splunk User Community,
Judopp
To reset the Splunk password, go to the directory and remove the passwd file. $SPLUNK_HOME
represents the directory where you installed Splunk.
cd $SPLUNK_HOME/etc
mv passwd old.passwd # for mac or linux
Then restart Splunk. The Splunk user will be "admin" and the password will be "changeme".
Any other existing users in the old file old.passwd
can be added back into the newly created passwd
file after the restart.
cheers, MuS