Getting Data In

Why can't I start the Splunk Forwarder on a local computer? (Error 1069, login failure)

brucelloyd1
New Member

Splunk Version 6.2.9.276372

Windows could not start the SplunkForwarder service on local computer. Error 1069: The service did not start due to a logon failure.

0 Karma

ddrillic
Ultra Champion

Similar issue at Error 1069 when starting splunkd using domain account

@ttchorz concluded by saying

-- ... I ended up creating a new user with different password and using that account to solve this problem.

0 Karma

amahoski
Explorer

Based on the error that you provided it sounds like the account that you are using to start the splunkd forwarder process most likely does not have the necessary level of permissions to start Splunk as a service. I would suggest checking windows services.msc and either update the account by re-entering the password(if it is incorrect), use an account with a higher permission level, or use a local system account(which is the default if you didn't specify an account when installing).

0 Karma

brucelloyd1
New Member

Well thanks for the suggestions. I just solved my own question.

I solved the Splunk issue which had the following error when I tried to start the SplunkForwarder service.

"Windows could not start the SplunkForwarder service on Local Computer. Error 1069: The service did not start due to a logon failure."

I fixed this error under the SplunkForwarder service properties. Under the Log On tab, I deselected the default radio button for “This account” and its accompanying “tis\splunk” user name and password and selected the radio button for “Local System account” and no box checked for “Allow service to interact with desktop.” Now the SplunkForwarder service starts OK with no errors.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...