<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there permissions for splunk user on universal forwarder for Windows? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/586431#M76161</link>
    <description>&lt;P&gt;Thanks for your inputs and replies. I was able to figure it out by granting the gMSA that we have running the Universal Forwarder service&amp;nbsp;read/write permissions to the registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security.&lt;/P&gt;&lt;P&gt;Once that was done all the security logs were flowing into our indexer.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Feb 2022 15:15:07 GMT</pubDate>
    <dc:creator>akyz</dc:creator>
    <dc:date>2022-02-24T15:15:07Z</dc:date>
    <item>
      <title>Are there permissions for splunk user on universal forwarder for Windows?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585414#M76112</link>
      <description>&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;We're deploying the Windows Universal Forwarder add-on to our environment and are using a gMSA. We have configured the basic permissions outlined here &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Installation/ChoosetheuserSplunkshouldrunas" target="_self"&gt;Choose the Windows user Splunk Enterprise should run as - Splunk Documentation&lt;/A&gt;. While we are now getting event log data ingested into Splunk Enterprise we do not see all the event log data. I believe we're missing Security. Is there any extra security permissions we're missing?&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Feb 2022 19:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585414#M76112</guid>
      <dc:creator>akyz</dc:creator>
      <dc:date>2022-02-16T19:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Are there permissions for splunk user on universal forwarder for Windows?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585434#M76113</link>
      <description>&lt;P&gt;Stupid question - do you have an input defined for the Security eventlog?&lt;/P&gt;&lt;P&gt;But if you do (that was just a quick check to see if you hadn't forgotten it) did you add your splunk user to the ACL on the Security eventlog? It's very ugly and it's done in the Registry by means of SDDL. So it's often way easier to just add your splunk user to local Eventlog Readers group (or something similarily named).&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 21:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585434#M76113</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-16T21:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Are there permissions for splunk user on universal forwarder for Windows?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585443#M76115</link>
      <description>&lt;P&gt;Yes the data inputs are defined and all event logs are selected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah I See the local event log readers group going to try that out. Does Splunk have any sort of documentation explaining all the permissions that are needed to properly ingest the data?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 22:00:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585443#M76115</guid>
      <dc:creator>akyz</dc:creator>
      <dc:date>2022-02-16T22:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Are there permissions for splunk user on universal forwarder for Windows?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585450#M76116</link>
      <description>&lt;P&gt;The article you cited gives a pretty good description of permissions and privileges needed for UF to run. But the permissions to specific event logs is another cup of tea... It's more of a "windows knowledge" than splunk knowledge. I remember having spent whole day until I found the logreaders group (but I was pulling logs with WMI).&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 23:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/585450#M76116</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-16T23:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Are there permissions for splunk user on universal forwarder for Windows?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/586431#M76161</link>
      <description>&lt;P&gt;Thanks for your inputs and replies. I was able to figure it out by granting the gMSA that we have running the Universal Forwarder service&amp;nbsp;read/write permissions to the registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security.&lt;/P&gt;&lt;P&gt;Once that was done all the security logs were flowing into our indexer.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 15:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Are-there-permissions-for-splunk-user-on-universal-forwarder-for/m-p/586431#M76161</guid>
      <dc:creator>akyz</dc:creator>
      <dc:date>2022-02-24T15:15:07Z</dc:date>
    </item>
  </channel>
</rss>

