This topic provides instructions for changing the admin password for the Security Analytics service and for the Security Analytics Core services.
The system administrator's user account is installed with Security Analytics. The username is admin and the default password is netwitness. The Administrators role is assigned to admin. This role has full system privileges to control what a user can do and which services a user can access. The only modification you can make to this account is to change the password. Unlike other Security Analytics users, changes to the admin user password do not automatically propagate to downstream services. When you configure the password strength settings, they apply to all Security Analytics users, including the admin user.
Passwords, an important aspect of computer security, are the front line of protection for your system. The admin user is pre-installed in Security Analytics and on each Security Analytics Core service. For security, you create the Users and Roles for your organization in Security Analytics, and on each Security Analytics Core service.
RSA recommends the following best practices:
- Change the admin password of each service from the default.
- Create a different password for the admin account on each service.
Change the admin Password for the Security Analytics Service
Change the admin password for the Security Analytics service in the Profile view. See Change Password in the Security Analytics Getting Started Guide. The password of the admin user does not propagate to Core services.
Note: After you change the admin password, you must remove and re-add a Data Source on the Reporting Engine. For more information, see the Remove and re-add a Data Source on the Reporting Engine section below.
Change the admin Password for Security Analytics Core Services
To change the admin password for a Core service:
- In the Security Analyticsmenu, select Administration > Services.
- Select a service, and then select > View > Security.
On the Users tab, select the admin user.
- In the Password field, type a new admin password for the selected service.
- In the Confirm Password field, retype the new password.
- Click Apply.
Note: After you change the admin password, you must remove and re-add a Data Source on the Reporting Engine. For more information, see Remove and re-add a Data Source on the Reporting Engine below.
Remove and re-add a Data Source on the Reporting Engine
Reporting Engine validates a Data Source using the Data Source username and password. If you change the username or password of a Data Source, you must remove and re-add the Data Source.
To remove and re-add a data source on the Reporting Engine:
- In the Security Analytics menu, select Administration > Services.
- In the Services view, select Reporting Engine and View > Config.
- Click the Sources tab.
- Select a service to remove and click
- Click and select Available Services.
- Select the service you removed in step 4 and click OK.
- When prompted, enter the new username and password for the service.
Change the admin Password for a Service Using the REST API
In rare circumstances, you may need to change the admin password for a Core service outside of the Security Analytics user interface. This is simply another way to perform the Security Analytics Core password change, and is not the preferred method.
To change the admin password for the service using the REST User Interface:
Open a web browser, and go to the following URL:
where the hostname is the name of a Security Analytics Core service and port is the port used for REST communication. Here is an example for a Security Analytics Decoder:
The authentication dialog is displayed.
In the dialog enter the user name and password used for authentication as admin on the service, and click OK. The default user name is admin and the default password is netwitness.
The REST window for the service is displayed.
Navigate through the node structure to users/accounts/admin/config.
The user configuration fields for admin are displayed in the browser window.
- In the Password field, type a new admin password and click Set.