If you are installing a splunk server (search, index, deploy) likely the splunk client software is running and using the same port. You need to remove the the following file:
mv /opt/splunkforwarder/etc/passwd /opt/splunkforwarder/etc/passwd.bak
Or
On Ubuntu
dpkg -l splunkforwarder (list the package)
dpkg -r splunkforwarder (remove the package)
Try login after, it should take admin/changeme.
... View more