Use PAM authentication
You can configure Splunk Enterprise to use PAM authentication by following the steps in the example directory's README, which is located at $SPLUNK_HOME/share/splunk/authScriptSamples/
.
If you are still unable to authenticate, then edit /etc/pam.d/pamauth
and add this line:
auth sufficient pam_unix.so