<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the admin account for on a Universal Forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407201#M72201</link>
    <description>&lt;P&gt;There are different contexts where CLI or REST access can be used or useful on a Splunk UF, you may want to refer to:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/CLIadmincommands"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/CLIadmincommands&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;On a UF specially, for trouble shooting you may run some commands like listing the file monitors, investigating the tailing processor, etc&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk _internal call /admin/inputstatus/TailingProcessor:FileStatus
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This requires an admin access on the UF.&lt;/P&gt;

&lt;P&gt;That being said, in real life in 99% of the cases you never never need to use a CLI or REST access on the UF, as a good practice we generally globally deactivate splunkd REST API on all standard UFs (not HFs !) via the deployment of a simple base config app, which is what I do and recommend to customers.&lt;BR /&gt;
Whenever you would such thing, you still can re-activate it, and again in most of the cases you don't need it because you would use for bad reasons most likely.&lt;/P&gt;

&lt;P&gt;Deactivating via server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[httpServer]
disableDefaultPort = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So good practice, at installation generate a random complex password for the admin account, and deactivate REST via the deployment of a base config app.&lt;/P&gt;

&lt;P&gt;Guilhem&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2019 21:33:03 GMT</pubDate>
    <dc:creator>guilmxm</dc:creator>
    <dc:date>2019-07-25T21:33:03Z</dc:date>
    <item>
      <title>What is the admin account for on a Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407200#M72200</link>
      <description>&lt;P&gt;I have UFs on some "sensitive" servers and the owners - that did the install are questioning the purpose of the Admin account.&lt;BR /&gt;
I have just accepted the fact that all splunk nodes require credentials and an account.&lt;BR /&gt;
Is there an official document or explanation for the reason a UF needs one?&lt;BR /&gt;&lt;BR /&gt;
These are windows servers.&lt;BR /&gt;
Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 21:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407200#M72200</guid>
      <dc:creator>Glasses</dc:creator>
      <dc:date>2019-07-25T21:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: What is the admin account for on a Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407201#M72201</link>
      <description>&lt;P&gt;There are different contexts where CLI or REST access can be used or useful on a Splunk UF, you may want to refer to:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/CLIadmincommands"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/CLIadmincommands&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;On a UF specially, for trouble shooting you may run some commands like listing the file monitors, investigating the tailing processor, etc&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk _internal call /admin/inputstatus/TailingProcessor:FileStatus
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This requires an admin access on the UF.&lt;/P&gt;

&lt;P&gt;That being said, in real life in 99% of the cases you never never need to use a CLI or REST access on the UF, as a good practice we generally globally deactivate splunkd REST API on all standard UFs (not HFs !) via the deployment of a simple base config app, which is what I do and recommend to customers.&lt;BR /&gt;
Whenever you would such thing, you still can re-activate it, and again in most of the cases you don't need it because you would use for bad reasons most likely.&lt;/P&gt;

&lt;P&gt;Deactivating via server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[httpServer]
disableDefaultPort = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So good practice, at installation generate a random complex password for the admin account, and deactivate REST via the deployment of a base config app.&lt;/P&gt;

&lt;P&gt;Guilhem&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 21:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407201#M72201</guid>
      <dc:creator>guilmxm</dc:creator>
      <dc:date>2019-07-25T21:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: What is the admin account for on a Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407202#M72202</link>
      <description>&lt;P&gt;Here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Choose_the_Windows_user_that_the_universal_forwarder_should_run_as"&gt;https://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Choose_the_Windows_user_that_the_universal_forwarder_should_run_as&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 20:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-admin-account-for-on-a-Universal-Forwarder/m-p/407202#M72202</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-26T20:06:51Z</dc:date>
    </item>
  </channel>
</rss>

