<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does the Windows Active Directory user for Splunk forwarder need &amp;quot;Remote Desktop access&amp;quot; rights? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373622#M67708</link>
    <description>&lt;P&gt;No, you would not need Remote Desktop access for that user.&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2017 14:28:35 GMT</pubDate>
    <dc:creator>kmorris_splunk</dc:creator>
    <dc:date>2017-05-11T14:28:35Z</dc:date>
    <item>
      <title>Does the Windows Active Directory user for Splunk forwarder need "Remote Desktop access" rights?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373619#M67705</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Does the Windows user for Splunk forwarder need "Remote Desktop access" rights?&lt;/P&gt;

&lt;P&gt;In general, what kind of Windows user/role/rights is recommended?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 10:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373619#M67705</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2017-05-11T10:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Windows Active Directory user for Splunk forwarder need "Remote Desktop access" rights?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373620#M67706</link>
      <description>&lt;P&gt;Take a look here (excerpt on choosing the Windows user below):&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Forwarder/6.5.3/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller"&gt;https://docs.splunk.com/Documentation/Forwarder/6.5.3/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Choose the Windows user that the universal forwarder should run as&lt;/STRONG&gt;&lt;BR /&gt;
When you install the universal forwarder, you can select the Windows user that the forwarder uses to get data. You have two choices.&lt;/P&gt;

&lt;P&gt;Local System. If you specify the Local System user during the installation process, the universal forwarder collects any kind of data that is available on the local host. It cannot collect data from other hosts.&lt;BR /&gt;
 Domain account. This option installs the forwarder as the Windows user you specify. The forwarder has the permissions that have been assigned to that user, and collects data that the user has read access to. It does not collect data from resources that the Windows user does not have access to. If you need to collect data from those resources, you must give the Windows user access to those resources.&lt;BR /&gt;
Install the forwarder as a Domain account to do any of the following:&lt;/P&gt;

&lt;P&gt;Read Event Logs remotely&lt;BR /&gt;
 Collect performance counters remotely&lt;BR /&gt;
 Read network shares for log files&lt;BR /&gt;
 Access the Active Directory schema, using Active Directory monitoring&lt;BR /&gt;
Choose and configure the user that the universal forwarder should run as before installing the forwarder for remote Windows data collection. If you do not, installation can fail.&lt;/P&gt;

&lt;P&gt;If you install as a domain user, specify a user that has access to the data you want to monitor. See Choose the Windows user Splunk should run as in the Splunk Enterprise Installation Manual for concepts and procedures on the user requirements that must be in place before you collect remote Windows data.&lt;/P&gt;

&lt;P&gt;If you install as a domain user, you can choose whether or not the user has administrative privileges on the local machine. If you choose not to give the user administrative privileges, the universal forwarder enables "low-privilege" mode. See Install the universal forwarder in low-privilege mode.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 11:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373620#M67706</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2017-05-11T11:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Windows Active Directory user for Splunk forwarder need "Remote Desktop access" rights?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373621#M67707</link>
      <description>&lt;P&gt;Thanks kmorris, could you confirm Remote Desktop access is not required then as we only index local files/registry?&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 12:09:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373621#M67707</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2017-05-11T12:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does the Windows Active Directory user for Splunk forwarder need "Remote Desktop access" rights?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373622#M67708</link>
      <description>&lt;P&gt;No, you would not need Remote Desktop access for that user.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 14:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-the-Windows-Active-Directory-user-for-Splunk-forwarder-need/m-p/373622#M67708</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2017-05-11T14:28:35Z</dc:date>
    </item>
  </channel>
</rss>

