Hi ,
I have installed a Universal Forwarder with a local system account, but now I want to make it in a domain account. Is it possible to change from Local System account to Domain account without uninstalling universal forwarder?
Yes, you can change service user, but you must make sure the user has permission to run powershell, perfmon, access windows event logs, WMI, etc. Additionally you will have to use iCacls to give ownership of the $SPLUNK_HOME directory to the new user.
Hi ,
Thank You! I wanted to know for windows forwarder and also the procedure to change that?
On windows, Go into the services control panel, find the Splunk Service and open it. There is a run as system / run as user option, you can change it to the user there.
Once completing you can restart the service and validate it starts correctly.
Is this a windows forwarder?
Hi ,
Yes this is windows forwarder.