Difference between user-seed.conf file and passwd file in splunk universal forwarder installation

Viewed 500

I am working on creation of automation script to install splunk universal forwarder. I wanted to understand more on user-seed.conf file and passwd file being created.

As we know, installing splunk UF asks for creation of administrator account when we start the splunk service and accept license.

Step 1:

/opt/splunkforwarder/bin/splunk start --accept-license --answer-yes

When we try to add forwarder to indexer connection , it asks us to authenticate with same username and password.

Step 2 :

 /opt/splunkforwarder/bin/splunk add forward-server test_server:9997

As per my understanding this authentication revolves around user-seed.conf file and passwd.conf file

user-seed.conf - $SPLUNK_HOME/etc/system/local
passwd - $SPLUNK_HOME/etc/passwd

Scenarios I faced :

  1. sometimes the authentication in step 2 was failing, in that case I saw only user-seed.conf file was created though I change admin username and password
  2. Authentication was successful in step 2 and here only passwd file was being created , though I changed username and password of admin.
  3. sometimes add forwarder was working with admin account authentication.

Now, my script is working and I am in point 2 . But I am stuck in understanding why the above scenarios happened ? The above scenarios are my observations, still I am unclear and confused.

Please can anyone help me in understanding this better ? what is the actual difference between user-seed and passwd conf file ? Why did I see only user-seed conf file being created and not passwd ?

Apologies , if my observations is completely wrong. I am newbiew to this. I went through many blogs over Internet, still not soo clear. Please help me with your inputs .

Thanks in advance, NVP

1 Answers

The user-seed.conf file is used only to load credentials when Splunk starts. Once the credentials are stored in etc/passwd user-seed.conf is deleted. Thereafter, only passwd is used to authenticate users.

You don't need credentials to configure a forwarder, though. All you need to do is edit the appropriate .conf file and then restart the forwarder.

Related