Renaming etc/passwd to passwd.bak and using user-seed.conf doesn't seem to work and I'm on a mac.
@splunk2day,
look here: https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/Secureyouradminaccount#Reset_a_lost_pass...
View solution in original post
Finally i could hard reset my admin pass from CLI using -
./splunk cmd splunkd rest --noauth POST /services/admin/users/admin "password=new8charpass"