Splunk
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    Release Notes

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics on-premises
    • AppDynamics Virtual Appliance
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
English Japanese
Log In Sign Up
English Japanese
Log In Sign Up
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    Release Notes

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics on-premises
    • AppDynamics Virtual Appliance
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
Share this page
  • LinkedIn
  • X
  • Facebook
  • Email
Splunk Cloud Platform
  • Administer
    • Manage Users and Security
      • Introduction to securing the Splunk platform
        • About securing the Splunk platform
        • How to secure and harden your Splunk platform instance
      • Manage Splunk platform users and roles
        • Use access control to secure Splunk data
        • About user authentication
        • About configuring role-based user access
        • Define roles on the Splunk platform with capabilities
        • Configure how capabilities grant access to Splunk resources and workflows with authorization policies
          • Create authorization policies in Splunk Web
          • Edit authorization policies in Splunk Web
          • Remove authorization policies in Splunk Web
        • Create and manage users with Splunk Web
        • Create and manage roles with Splunk Web
        • Find existing users and roles
        • Secure access for Splunk knowledge objects
        • Manage Splunk Cloud Platform users and roles
      • Manage credentials and keys
        • Password best practices for administrators
        • Configure Splunk password policies
        • Configure a Splunk Enterprise password policy using the Authentication.conf configuration file
        • Password best practices for users
        • Unlock a user account
        • Change a user password
        • Manage out-of-sync passwords in a search head cluster
        • Secure data with Enterprise Managed Encryption Keys
      • Use the native Splunk platform authentication scheme
        • Set up native Splunk authentication
      • Use LDAP as an authentication scheme
        • Set up user authentication with LDAP
        • Manage Splunk user roles with LDAP
        • LDAP prerequisites and considerations
        • Secure LDAP authentication with transport layer security (TLS) certificates
        • How the Splunk platform works with multiple LDAP servers for authentication
        • Configure LDAP with Splunk Web
        • Map LDAP groups to Splunk roles in Splunk Web
      • Use SAML as an authentication scheme for single sign-on
        • Configure single sign-on with SAML
        • Configure SSO with PingIdentity as your SAML identity provider
        • Configure SSO with Okta as your identity provider
        • Configure SSO with Microsoft Azure AD or AD FS as your Identity Provider
        • Configure SSO with OneLogin as your identity provider
        • Configure SSO with Optimal as your identity provider
        • Configure SSO in Computer Associates (CA) SiteMinder
        • Secure SSO with TLS certificates on Splunk Enterprise
        • Configure Ping Identity with leaf or intermediate SSL certificate chains
        • Configure SAML SSO for other IdPs
        • Configure authentication extensions to interface with your SAML identity provider
        • Configure advanced settings for SSO
        • Map groups on a SAML identity provider to Splunk roles
        • Modify or remove role mappings
        • Refresh expiring SAML identity provider certificates
        • Troubleshoot SAML SSO
      • Authenticate into the Splunk platform with tokens
        • Set up authentication with tokens
        • Configure Splunk Cloud Platform to use SAML for authentication tokens
        • Enable or disable token authentication
        • Create authentication tokens
        • Manage or delete authentication tokens
        • Use authentication tokens
        • Troubleshoot token authentication
      • Configure the Splunk platform with External Authentication and Authorization
        • Configure an external Open Authorization 2.0 authorization server
        • Define an OAuth 2.0 external application server
        • Map groups from the client application on the identity provider to Splunk roles
      • Secure Splunk platform communications with Transport Layer Security certificates
        • Configure mutually authenticated transport layer security (mTLS) on the Splunk platform
      • Use field filters to protect sensitive data
        • Protect PII, PHI, and other sensitive data with field filters
        • Plan for field filters in your organization
          • Create, manage, and test your field filters
          • Indexes, hosts, sources, and source types
          • Fields and field values
          • Field filter naming and quantity
          • Roles and permissions
          • READ THIS: Downstream impact of field filters
          • READ THIS: Restricted commands do not work in searches on indexes that have field filters
          • Optimize performance
          • Upgrades and migration
          • Limitations on using field filters in your environment
        • Create field filters using Splunk Web
        • Optimize field filter performance using Splunk Web
        • Exempt certain roles from field filters using Splunk Web
        • Use field filters in searches
          • Limit search terms using search filters
          • Support for generating commands
          • Support for tstats in searches on indexes with field filters
          • Support for walklex and typeahead in searches on indexes with field filters
          • Examples of searches with field filters
        • Use field filters in searches on accelerated data models
          • How field filters work in accelerated data models
          • Protect sensitive fields in DMA-summarized data
          • Search-time order and DMA
          • Filtered and original field values in summary indexes
        • Turn off Splunk platform field filters
      • Audit activity in the Splunk platform
        • Use the Splunk platform to audit your system activity
        • Auditing activities in a Splunk platform instance
        • Use audit events to detect threats and secure data in the Splunk platform
        • About structured audit trail logs
      • Private connectivity
        • About private connectivity
        • Enable private connectivity
      • Best practices for Splunk platform security
        • SPL safeguards for risky commands
        • Troubleshoot Splunk forwarder TCP tokens
        • Avoid unintentional execution of fields within CSV files in third party applications
Splunk Cloud Platform › Administer › Manage Users and Security › Manage credentials and keys

Manage out-of-sync passwords in a search head cluster

If passwords become out-of-sync in your search head cluster, you can force replication on the cluster to sync your passwords. See Use the deployer to distribute apps and configuration updates.

Share feedback about this page
Previous Change a user password Next Secure data with Enterprise Managed Encryption Keys
logo
x facebook linkedin youtube instagram
©2005-2026 Splunk Inc. All rights reserved.
Legal Privacy Website Terms of Use