Getting Data In

What are the limitations of installing/running the UF in low privilege mode?

bo055677
New Member

I'm getting push back on installing UFs on domain controllers and I believe installing in low privilege mode is the solution which will meet windows administrators concerns. My only issue is that I haven't been able to find a document that states the exact limitations of running the UF in low privilege mode, other than this article.

https://answers.splunk.com/answers/93998/running-universal-forwarder-with-non-administrator-service-...

Does anyone know if there is a document on what a low privilege UF can't do?

Will this let me run Powershell commands?

0 Karma

nickhills
Ultra Champion

A low privileged user on windows will not be able to access the windows event logs without some additional configuration in your AD audit settings (and potentially a significant amount of pain)

An alternative to this is to run a collector to perform remote log collection, however this is only marginally better, because you have now given a remote system a privileged logon to the domain controllers.

Its only right to point out that this is a limitation of windows, rather than splunk, but my advice is to keep up the fight.
The value (and speed/volume advantage over remote wmi) of a local installed forwarder with sufficient rights is worth it over the headaches in the future.

If remote deployment is a concern (or the ability to do so) I would suggest locally deployed apps (ie no deployment server) over the alternatives - or even better a separate DS just to manage your sensitive deployment clients.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...