Network Management
Manage SolarWinds Platform Service Accounts
Learn what accounts are created automatically by the SolarWinds Platform and SolarWinds Platform products and how you can reset or rebuild them if needed.
First published date
Last published date
Overview
This article describes the accounts created by the SolarWinds Platform and SolarWinds Platform products that are not defined by the administrator. These accounts are automatically generated during the configuration of the product, a particular feature, or an integration.
Product section
Cause
Resolution
See the following sections for product-specific information:
- Orion Platform/SolarWinds Platform
- Database Portfolio Analyzer Integration Module (DPAIM)
- Enterprise Operations Console (EOC)
- Server & Application Monitor (SAM)
- SolarWinds Service Desk (SWSD)
- Storage Resource Monitor (SRM) and Storage Manager/ Storage Profiler (STM) (Legacy)
- Virtualization Manager (VMAN)
- Web Help Desk (WHD)
- Web Performance Monitor (WPM)
SolarWinds Platform
| Service Account Name | Description |
|---|---|
|
_system |
This account is automatically generated by the Configuration Wizard. It is specifically used for internal communication between SolarWinds services. The password is randomly generated and encrypted by a certificate stored on the SolarWinds Platform. It is primarily used between SolarWinds Information Service v3 and SolarWinds Orion Module Engine service to communicate to SolarWinds Cortex service via its HTTP API. The account requires admin privileges. Steps to reset or rebuild the account:
|
|
Erlang cookie |
The main purpose of the Erlang.cookie is to secure and authenticate communication between RabbitMQ nodes in a high availability (HA) cluster. The RabbitMQ server uses Erlang as a virtual machine and usually runs on the main polling engine. When HA is enabled, the RabbitMQ server also runs on the backup server and a RabbitMQ cluster is created. In an HA setup, the Erlang cookie file needs to be the same on all members of the main polling engine pool. This is accomplished by storing the encrypted cookie value in the database credential store. More information can be found in the RabbitMQ documentation: https://www.rabbitmq.com/clustering.html#erlang-cookie (©Copyright 2007-2020 VMware, Inc., available at https://www.rabbitmq.com/, obtained on February 3, 2021) Steps to reset or rebuild the account: To reset the Erlang cookies, see the following procedures: |
|
JobEngine |
The Job Engine router TCP endpoint credentials are generated by the Configuration Wizard. This account is used for internal communication between the JobEngine service and the SolarWinds services that use it (for example, the Collector and Business Layer services). Steps to reset or rebuild the account: To reset this account, administrators must delete records from the database and run the Configuration Wizard to recreate them.
|
| Macro | This SQL database role is limited to accessing non-sensitive data. |
| MacroClient | This is a SQL database user without login and without a password. It is used by the SolarWinds Alerting Engine to execute SQL queries for the SQL macro variables. It is limited to accessing non-sensitive data only. |
| OIP | This SQL database role is a member of the SQL db_datareader role with limited access to sensitive tables. |
| OIPClient |
This is a SQL database user without a login and without a password. It is a member of the OIP DB role. It is used in the OIP Client to collect and send Orion Improvement information from the Orion database in read-only mode with limited access to sensitive tables. |
| Orion Agent - "swiagent" |
The Orion Linux Agent daemon runs under a local dedicated 'swiagent' user account and 'swiagent' group that is created when the agent is first installed. This is a least-privileged account and cannot be used to authenticate to the system remotely via methods such as SSH. It is also possible to change the user account the Linux Agent daemon runs under, but this is not recommended and not officially supported at this time. Note that any non-local Linux system monitoring requires additional credentials to be specified when it is initially configured through the Orion web interface. For example, the monitoring of MySQL, JBoss, PostgreSQL, etc. all require additional credentials to be specified because the account the Agent daemon runs under does not have sufficient privileges to monitor these types of applications. The Windows Agent service runs under the local system account. This the same account used to run virtually all native and non-native Windows services. While the account the Orion Windows Agent service runs under can be changed, this has not been thoroughly tested, is not recommended, and not officially supported at this time. Note that any non-local Windows OS system monitoring requires additional credentials to be specified when it is initially configured through the Orion web interface. For example, monitoring MSSQL, Oracle, Exchange, etc. all require additional credentials to be specified because the local system account that the Agent service runs under does not have sufficient privileges to monitor these types of applications. Steps to reset or rebuild the account: N/A |
|
RabbitMQ |
RabbitMQ is a third-party (open source) message broker software shipped with the SolarWinds Platform. It acts as a “middleman” and accepts messages from Orion components (producers) and delivers them to other Orion components (consumers). To connect to RabbitMQ, every producer and subscriber needs a username and password. The fixed username "orion" and a randomly generated password are generated when the Configuration Wizard initially runs. They are stored in the Orion credential store. This account is given superuser access within RabbitMQ. There is also a RabbitMQ management console that allows users to monitor and manage RabbitMQ from a web browser using the same credentials. If there is any suspicion that RabbitMQ server is compromised, rebuild the account as described below. Steps to reset or rebuild the account: To rebuild the RabbitMQ user account, follow the instructions in these KB articles: |
| Reporting | SolarWinds Platform 2023.2 and later This SQL database role is limited to querying/reading non-sensitive data only from the SolarWinds Platform (SolarWindsOrion) database. |
| ReportingClient | SolarWinds Platform 2023.2 and later
This is a SQL database user without login and without a password. It is a member of the Reporting role. It is used by the SolarWinds Platform to execute SQL queries for Reports that use SQL Query Datasources. The user is limited to querying/reading non-sensitive data only from the SolarWinds Platform (SolarWindsOrion) database. |
| WebsiteMaintenance_user |
This non-administrator account with no privileges is created automatically to speed up starting the website when accessing the Web Console for the first time after restarting the server or running the Configuration Wizard.
The Web Console starts more slowly when run for the first time but the WebsiteMaintenance_user account will not appear anymore. |
Database Portfolio Analyzer Integration Module (DPAIM)
| Service Account Name | Description |
|---|---|
|
DPAServiceUser_.... |
This account is used to establish a federated SWIS connection between Database Portfolio Analyzer (DPA) and the Orion Platform. Steps to reset or rebuild the account: The password is generated and users cannot choose or change it. However, if there is a need for a new service account with a new password, you can:
|
|
__DPA.Service.Account_... |
DPAIM creates a service account in DPA and these are the credentials for it. It is created during the integration process because it needs to establish a communication channel without storing admin credentials (needed for integration initialization). Steps to reset or rebuild the account: The password is generated and users cannot choose or change it. However, if there is a need for a new service account with a new password, you can:
|
Enterprise Operations Console (EOC)
| Service Account Name | Description |
|---|---|
|
EocSystemAccount-X |
This is a system account used by EOC to gather information from remote instances. It is created on remote instances. Steps to reset or rebuild the account: Removing the site associated with the system account from EOC should remove the account. Then you can re-add the site, and a new account will be created. See Add a SolarWinds Site to EOC in the EOC Administrator Guide. If the method above doesn't work, an alternative option is to delete the account from the database and re-add the EOC site. The following script is an example:
|
|
EocSubscription |
(Present on remote instances.) This account is used to authenticate remote sites communicating back to EOC about possible schema changes (for example, when a custom property has been added). The password for this account is created dynamically each time SWIS is started in EOC. Steps to reset or rebuild the account: Restart SWIS on the EOC side. This generates new credentials on each EOC site. |
Server & Application Monitor (SAM)
| Service Account Name | Description |
|---|---|
|
Container Monitoring |
Container Monitoring within the SolarWinds Platform requires an Admin Account. For more information, see: Kubernetes resources created:
Steps to reset or rebuild the account: To remove the resources listed above:
|
SolarWinds Service Desk (SWSD)
| Service Account Name | Description |
|---|---|
|
Windows local system account root privileges (sudo) on Linux root privileges on OSX |
There is no need to change passwords due to the type of accounts used. This information is applicable to the discovery scanners and agents. Steps to reset or rebuild the account: N/A |
Storage Resource Monitor (SRM) and Storage Manager/ Storage Profiler (STM) (Legacy)
| Service Account Name | Description |
|---|---|
|
STMServiceUser_randomstring |
This service account is used to sync license information between SRM and STM (SRM Profiler). The password generated for a service account is a random password when the integration is set up and exchanged between SRM and STM (SRM Profiler) using their SWIS credentials. Steps to reset or rebuild the account: To reset or change the password, disable and enable integration to re-generate a new service account password. See: If integration with STM (SRM Profiler) is not enabled, any Orion accounts starting with "STMServiceUser_" can be safely removed.
|
Virtualization Manager (VMAN)
| Service Account Name | Description |
|---|---|
|
VMANServiceUser_ |
This service account is used for VMAN to VMAN Appliance (legacy Linux-based VM appliance) integration. During the creation of the first account, the Orion Service account is also created. Steps to reset or rebuild the account: If integration with the legacy VMAN appliance is not used, simply delete all Orion accounts starting with "VMANServiceUser_":
If integration with the VMAN appliance is used, disable integration with the VMAN appliance, delete the account 'VMANServiceUser_' (using the steps above), and then enable integration again. |
Web Help Desk (WHD)
| Service Account Name | Description |
|---|---|
|
WHDNotificationUser_ |
This service account is used by WHD to integrate with the SolarWinds Platform and create tickets in WHD from alerts. The account is used to subscribe to alerts. Steps to reset or rebuild the account: The username and password are dynamically generated when a new source is created. To reset the password, delete and recreate the source in WHD under SolarWinds integration. |
|
whd |
When WHD is installed, it also installs a PostgreSQL server that is used in case the client wants to use the embedded database option. During the installation, a PostgreSQL user is created with the username 'whd' and password 'whd'. Steps to reset or rebuild the account: Connect to the PostgreSQL server with the user 'whd' and change the password by issuing the following SQL command:
|
|
LocalSystem account |
The Windows account 'LocalSystem' is used to run the Tomcat service behind WHD as a Windows Service. The same account is also used to run the embedded PostgreSQL server as a service. Steps to reset or rebuild the account: N/A |
Web Performance Monitor (WPM)
| Service Account Name | Description |
|---|---|
|
AesKeyIVCredentials |
This is the AES Key and Initialization Vector for AES algorithm. It is used to encrypt and decrypt user recordings in the Orion database. Steps to reset or rebuild the account: To recreate the AES key, complete the following steps. (Note: All historical data from all transactions will be lost.)
|
|
SEUM-User-# |
These Windows accounts are created on each machine where the WPM player is installed. They are used by the WPM agent for playbacks. Passwords are randomly generated by default, require local admin privileges, and are stored locally in the C:\ProgramData\SolarWinds\SEUM\Data\AgentSettings.dat file. They can be replaced with domain accounts, and SolarWinds recommends deploying dedicated WPM player machines per WPM location. Steps to reset or rebuild the account:
To remove all SEUM-User accounts and recreate them:
|
|
SolarWinds-SEUM-Users |
This local group is created automatically and contains the SEUM-User-# accounts used for WPM players during playback. Steps to reset or rebuild the account: To change the group name:
|