Getting Data In

What are the limitations of installing/running the UF in low privilege mode?

bo055677
New Member

I'm getting push back on installing UFs on domain controllers and I believe installing in low privilege mode is the solution which will meet windows administrators concerns. My only issue is that I haven't been able to find a document that states the exact limitations of running the UF in low privilege mode, other than this article.

https://answers.splunk.com/answers/93998/running-universal-forwarder-with-non-administrator-service-...

Does anyone know if there is a document on what a low privilege UF can't do?

Will this let me run Powershell commands?

0 Karma

nickhills
Ultra Champion

A low privileged user on windows will not be able to access the windows event logs without some additional configuration in your AD audit settings (and potentially a significant amount of pain)

An alternative to this is to run a collector to perform remote log collection, however this is only marginally better, because you have now given a remote system a privileged logon to the domain controllers.

Its only right to point out that this is a limitation of windows, rather than splunk, but my advice is to keep up the fight.
The value (and speed/volume advantage over remote wmi) of a local installed forwarder with sufficient rights is worth it over the headaches in the future.

If remote deployment is a concern (or the ability to do so) I would suggest locally deployed apps (ie no deployment server) over the alternatives - or even better a separate DS just to manage your sensitive deployment clients.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...