<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder on Windows - Administrator Credential in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584560#M11537</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;That is for Splunk’s internal admin user. Normally it’s not used in UF, but time by time there could be some situations when those are useful.&amp;nbsp;&lt;BR /&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 16:54:09 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-02-10T16:54:09Z</dc:date>
    <item>
      <title>What is the purpose of Universal Forwarder on Windows - Administrator Credential?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584558#M11536</link>
      <description>&lt;P&gt;I'm running Splunk Enterprise 8.2.4. When deploying the Universal Forwarder for Windows (version 8.2.4) and selecting to run it under the Local System account it subsequently asks me for the 'create&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;credentials for the administrator accoun&lt;/STRONG&gt;&lt;/EM&gt;t' as per attached. What is the purpose of this ?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 16:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584558#M11536</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-10T16:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder on Windows - Administrator Credential</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584560#M11537</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;That is for Splunk’s internal admin user. Normally it’s not used in UF, but time by time there could be some situations when those are useful.&amp;nbsp;&lt;BR /&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 16:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584560#M11537</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-10T16:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: What is the purpose of Universal Forwarder on Windows - Administrator Credential?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584561#M11538</link>
      <description>&lt;P&gt;It's a misunderstanding. One thing is the windows user the application runs with - Local System or a particular local/domain account. That's configured on a previous screen.&lt;/P&gt;&lt;P&gt;What you're showing is a local splunk uf user - it's a internal splunk authentication method. It's needed if you - for example run splunk btool command or create inputs/outputs by means of cli&amp;nbsp; commands. You have to provide this user's credentials in order to manipulate splunk installation.&lt;/P&gt;&lt;P&gt;So you might run UF as Local System or Your_Domain\splunk or whatever user you want but you create a user _within splunk uf_ for some administrative tasks.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 17:07:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584561#M11538</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-10T17:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is the purpose of Universal Forwarder on Windows - Administrator Credential?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584572#M11539</link>
      <description>&lt;P&gt;OK but I have run the &lt;STRONG&gt;btool&lt;/STRONG&gt; command from the UF (for example) on Windows and have never been prompted for this credential. That said, I'm always logging into my Windows Server System as an OS admin user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I MUST specify it using the UI installer though. I can understand that you might use this as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have a script that has standard non-elevated OS user rights on Windows and hence cannot access the underlying conf files&lt;/LI&gt;&lt;LI&gt;You want this script to configure the UF&lt;/LI&gt;&lt;LI&gt;The Splunk forwarder credential used during setup can be assigned to the script for this usage&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I will test this hypothesis.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 18:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584572#M11539</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-10T18:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: What is the purpose of Universal Forwarder on Windows - Administrator Credential?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584612#M11543</link>
      <description>&lt;P&gt;Ok, maybe btool doesn't require it (I don't usually run it on UFs so I might nit remember exactly but listing input status needed authenticating for sure)&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 22:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/584612#M11543</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-10T22:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: What is the purpose of Universal Forwarder on Windows - Administrator Credential?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/585232#M11582</link>
      <description>&lt;P&gt;The following command will ask for the admin password on windows UF:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;splunk monitor list&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As such, I agree that&amp;nbsp; the admin password appears to be required for Splunk based auth to run certain commands. Makes a lot of sense actually as separates the software to a degree form the OS auth model.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 20:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-the-purpose-of-Universal-Forwarder-on-Windows/m-p/585232#M11582</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-15T20:41:07Z</dc:date>
    </item>
  </channel>
</rss>

