Getting Data In

If I installed a universal forwarder with a local system account, is it possible to change to a domain account without uninstalling the forwarder?

Abilan1
Path Finder

Hi ,

I have installed a Universal Forwarder with a local system account, but now I want to make it in a domain account. Is it possible to change from Local System account to Domain account without uninstalling universal forwarder?

0 Karma

bmacias84
Champion

Yes, you can change service user, but you must make sure the user has permission to run powershell, perfmon, access windows event logs, WMI, etc. Additionally you will have to use iCacls to give ownership of the $SPLUNK_HOME directory to the new user.

0 Karma

Abilan1
Path Finder

Hi ,

Thank You! I wanted to know for windows forwarder and also the procedure to change that?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

On windows, Go into the services control panel, find the Splunk Service and open it. There is a run as system / run as user option, you can change it to the user there.
Once completing you can restart the service and validate it starts correctly.

0 Karma

somesoni2
Revered Legend

Is this a windows forwarder?

0 Karma

Abilan1
Path Finder

Hi ,

Yes this is windows forwarder.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...