Getting Data In

If I installed a universal forwarder with a local system account, is it possible to change to a domain account without uninstalling the forwarder?

Abilan1
Path Finder

Hi ,

I have installed a Universal Forwarder with a local system account, but now I want to make it in a domain account. Is it possible to change from Local System account to Domain account without uninstalling universal forwarder?

0 Karma

bmacias84
Champion

Yes, you can change service user, but you must make sure the user has permission to run powershell, perfmon, access windows event logs, WMI, etc. Additionally you will have to use iCacls to give ownership of the $SPLUNK_HOME directory to the new user.

0 Karma

Abilan1
Path Finder

Hi ,

Thank You! I wanted to know for windows forwarder and also the procedure to change that?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

On windows, Go into the services control panel, find the Splunk Service and open it. There is a run as system / run as user option, you can change it to the user there.
Once completing you can restart the service and validate it starts correctly.

0 Karma

somesoni2
Revered Legend

Is this a windows forwarder?

0 Karma

Abilan1
Path Finder

Hi ,

Yes this is windows forwarder.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...