How to Reset the Forgotten Password of Admin in Splunk

Suppose someone is the admin of the Splunk and he has forgotten the password.

Now we will show you how to reset the password of admin very easily.

Step 1:

Open the command prompt/terminal of your system. Find the passwd file( $SPLUNK_HOME/etc/passwd ) of Splunk and rename it as passwd.bk.

# cd /opt/splunk/etc

# ls

# mv /opt/splunk/etc/passwd  /opt/splunk/etc/passwd.bk


Step 2:

Create a .conf file names user-seed.conf  in your $SPLUNK_HOME/etc/system/local directory.

# cd /opt/splunk/etc/system/local

# vi user-seed.conf







In the above screen shot  user name is admin  and new password is 12345678.

After adding this file and restart Splunk then you will be able to login in your system with your new password what you have mentioned in the user-seed.conf file.

# /opt/splunk/bin/splunk restart



Also the you can see that new passwd file will be created in the $SPLUNK_HOME/etc directory.

Step 3:


If there are users previously created by you and they know their own credentials then copy and paste their credentials from the passwd.bk file to new passwd file and then restart Splunk. You have to copy and paste all the credentials of existing users except admin.

 # /opt/splunk/bin/splunk restart

So finally we have reset the password  of the admin in Splunk.


Hope, this has helped you in achieving the below requirement without fail:

How to Reset the Forgotten Password of Admin in Splunk


Happy Splunking  !!