Splunk
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    Release Notes

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics on-premises
    • AppDynamics Virtual Appliance
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
English Japanese
Log In Sign Up
English Japanese
Log In Sign Up
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    Release Notes

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics on-premises
    • AppDynamics Virtual Appliance
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
Share this page
  • LinkedIn
  • X
  • Facebook
  • Email
Splunk Enterprise
  • Administer
    • Manage Users and Security
      • Introduction to securing the Splunk platform
        • About securing the Splunk platform
        • How to secure and harden your Splunk platform instance
        • Security updates
      • Install Splunk Enterprise securely
        • Install Splunk Enterprise securely
        • Create secure administrator credentials
        • About TLS encryption and cipher suites
        • Harden the Splunk Enterprise installation directory on Windows
        • Secure Splunk Enterprise on your network
        • Disable unnecessary Splunk Enterprise components
        • Secure Splunk Enterprise service accounts
        • Deploy secure passwords across multiple servers
        • Harden the network port that App Key Value Store uses
        • Use network access control lists to protect your Splunk Enterprise deployment
      • Establish and maintain compliance with FIPS and Common Criteria in Splunk Enterprise
        • Secure Splunk Enterprise with FIPS
        • Best practice for maintaining compliance with FIPS and Common Criteria in your Splunk Enterprise environment
      • Manage Splunk platform users and roles
        • Use access control to secure Splunk data
        • About user authentication
        • About configuring role-based user access
        • Define roles on the Splunk platform with capabilities
        • Create and manage users with Splunk Web
        • Create and manage roles with Splunk Web
        • Find existing users and roles
        • Secure access for Splunk knowledge objects
      • Perform advanced user and role management in Splunk Enterprise
        • Create and manage roles in Splunk Enterprise using the authorize.conf configuration file
        • Configure users with the CLI
        • Configure access to manager consoles and apps in Splunk Enterprise
        • Delete all user accounts on Splunk Enterprise
      • Manage credentials and keys
        • Password best practices for administrators
        • Configure Splunk password policies
        • Configure a Splunk Enterprise password policy using the Authentication.conf configuration file
        • Password best practices for users
        • Unlock a user account
        • Change a user password
        • Manage out-of-sync passwords in a search head cluster
      • Use the native Splunk platform authentication scheme
        • Set up native Splunk authentication
      • Use LDAP as an authentication scheme
        • Set up user authentication with LDAP
        • Manage Splunk user roles with LDAP
        • LDAP prerequisites and considerations
        • Secure LDAP authentication with transport layer security (TLS) certificates
        • How the Splunk platform works with multiple LDAP servers for authentication
        • Configure LDAP with Splunk Web
        • Map LDAP groups to Splunk roles in Splunk Web
      • Perform advanced configuration of LDAP authentication in Splunk Enterprise
        • Configure LDAP using configuration files
        • Map LDAP groups and users to Splunk roles using configuration files
        • Change authentication schemes from native to LDAP on Splunk Enterprise
        • Remove an LDAP user safely on Splunk Enterprise
        • Test your LDAP configuration on Splunk Enterprise
      • Use SAML as an authentication scheme for single sign-on
        • Configure single sign-on with SAML
        • Configure SSO with PingIdentity as your SAML identity provider
        • Configure SSO with Okta as your identity provider
        • Configure SSO with Microsoft Azure AD or AD FS as your Identity Provider
        • Configure SSO with OneLogin as your identity provider
        • Configure SSO with Optimal as your identity provider
        • Configure SSO in Computer Associates (CA) SiteMinder
        • Secure SSO with TLS certificates on Splunk Enterprise
        • Configure Ping Identity with leaf or intermediate SSL certificate chains
        • Configure SAML SSO for other IdPs
        • Configure authentication extensions to interface with your SAML identity provider
        • Configure advanced settings for SSO
        • Map groups on a SAML identity provider to Splunk roles
        • Modify or remove role mappings
        • Refresh expiring SAML identity provider certificates
        • Troubleshoot SAML SSO
      • Perform advanced configuration of SAML authentication in Splunk Enterprise
        • Configuring SAML in a search head cluster
        • Best practices for using SAML as an authentication scheme for single-sign on
        • Configure SAML SSO using configuration files on Splunk Enterprise
      • Use multi-factor authentication in Splunk Enterprise as an authentication scheme
        • About multifactor authentication with Duo Security
        • Configure Splunk Enterprise to use Duo Security multifactor authentication
        • Configure Duo multifactor authentication for Splunk Enterprise in the configuration file
        • Migrate from the Duo Traditional Prompt to the Duo Universal Prompt
        • About multifactor authentication with RSA Authentication Manager
        • Configure RSA authentication from Splunk Web
        • Configure Splunk Enterprise to use RSA Authentication Manager multifactor authentication via the REST endpoint
        • Configure Splunk Enterprise to use RSA Authentication Manager multifactor authentication in the configuration file
        • User experience when logging into a Splunk instance configured with RSA multifactor authentication
      • Authenticate into the Splunk platform with tokens
        • Set up authentication with tokens
        • Configure Splunk Cloud Platform to use SAML for authentication tokens
        • Enable or disable token authentication
        • Create authentication tokens
        • Manage or delete authentication tokens
        • Use authentication tokens
        • Troubleshoot token authentication
      • Authenticate into Splunk Enterprise using single sign-on with reverse proxy
        • About single sign-on using reverse proxy
        • Configure Single Sign-On with reverse proxy
        • Troubleshoot reverse-proxy SSO
      • Authenticate into Splunk Enterprise using hardware
        • Configure Splunk Enterprise to use a common access card for authentication
      • Authenticate into Splunk Enterprise using scripts
        • Set up user authentication with external systems
        • Create the authentication script
        • Connect your authentication system with Splunk Enterprise using the authentication.conf configuration file
        • Use PAM authentication
        • Use the getSearchFilter function to filter at search time
      • Secure Splunk platform communications with Transport Layer Security certificates
        • Introduction to securing the Splunk platform with TLS
        • Steps for securing your Splunk Enterprise deployment with TLS
        • How to obtain certificates from a third-party for inter-Splunk communication
        • How to obtain certificates from a third-party for Splunk Web
        • How to create and sign your own TLS certificates
        • How to prepare TLS certificates for use with the Splunk platform
        • Configure Splunk indexing and forwarding to use TLS certificates
        • Configure TLS certificates for inter-Splunk communication
        • Configure Splunk Web to use TLS certificates
        • Test and troubleshoot TLS connections
        • Renew existing TLS certificates
        • Configure TLS certificate host name validation for secured connections between Splunk software components
        • Configure SSL and TLS protocol version support for secure connections between Splunk platform instances
        • Configure and install certificates in Splunk Enterprise for Splunk Log Observer Connect
      • Secure communications between Splunk Web and your browser
        • Secure Splunk Web communications
        • Turn on HTTPS encryption for Splunk Web with Splunk Web
        • Turn on HTTPS encryption for Splunk Web using the web.conf configuration file
      • Secure distributed and clustered Splunk environments
        • Configure secure communications between Splunk instances with updated cipher suite and message authentication code
        • Securing distributed search heads and peers
        • Secure deployment servers and clients using certificate authentication
        • Configure communication and bundle download authentication for deployment servers and clients
        • Secure Splunk Enterprise services with pass4SymmKey
      • Use role-based field filtering to protect sensitive data
        • Protecting PII and PHI data with role-based field filtering
        • Planning for role-based field filtering in your organization
        • Turning on Splunk platform role-based field filtering
        • Setting role-based field filters with the Splunk platform
        • Limiting role-based field filters to specific hosts, sources, indexes, and source types
        • Turning off Splunk platform role-based field filtering
      • Audit activity in Splunk Enterprise
        • Use Splunk Enterprise to audit your system activity
        • Audit Splunk activity
        • Use audit events to secure Splunk Enterprise
        • Manage data integrity
      • Best practices for Splunk platform security
        • SPL safeguards for risky commands
        • Some best practices for your servers and operating system
        • Troubleshoot Splunk forwarder TCP tokens
        • Avoid unintentional execution of fields within CSV files in third party applications
Splunk Enterprise › Administer › Manage Users and Security › Manage credentials and keys

Manage out-of-sync passwords in a search head cluster

If passwords become out-of-sync in your search head cluster, you can force replication on the cluster to sync your passwords. See Use the deployer to distribute apps and configuration updates.

Share feedback about this page
Previous Change a user password Next Use the native Splunk platform authentication scheme
logo
x facebook linkedin youtube instagram
©2005-2026 Splunk Inc. All rights reserved.
Legal Privacy Website Terms of Use