<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UF install via Intune in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/683250#M13778</link>
    <description>&lt;P&gt;Recent versions of the Splunk Universal Forwarder install with a least privileged user that doesn't have the ability to pull Windows event logs by default.&amp;nbsp; This is different from older versions of the UF which worked differently and could pull all logs by default.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not familiar with what you can do with Intune, but do you have the ability to specify command line arguments to run with the deployment? I'm thinking you may need to add something like&amp;nbsp;&lt;SPAN&gt;WINEVENTLOG_SEC_ENABLE=1 (or similar).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Supported_command_line_flags" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Supported_command_line_flags&lt;/A&gt;&amp;nbsp;for details along with other supported options.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2024 13:22:40 GMT</pubDate>
    <dc:creator>tkopchak</dc:creator>
    <dc:date>2024-04-04T13:22:40Z</dc:date>
    <item>
      <title>Splunk UF install via Intune</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/677652#M13656</link>
      <description>&lt;P&gt;Looking for some advice please!&lt;/P&gt;&lt;P&gt;I have pushed Splunk UF via MS Intune to all domain laptops. All looks well with config file and settings for reporting server and ports set.&lt;/P&gt;&lt;P&gt;On an example machine, go to services, SplunkForwarder is running.&lt;/P&gt;&lt;P&gt;These logs are meant to be pushed to our CyberDefence 3rd party.&amp;nbsp; However, it seems Splunk has no rights to send logs (possibly due to 'Log on' as settings in SplunkForwarder service).&lt;/P&gt;&lt;P&gt;Has anyone ever encountered this before and resolved, or completed Spunk UF install via Intune?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 12:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/677652#M13656</guid>
      <dc:creator>Steven73</dc:creator>
      <dc:date>2024-02-15T12:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF install via Intune</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/677674#M13658</link>
      <description>&lt;P&gt;The configs may *look* well, but maybe they aren't.&amp;nbsp; Share the inputs.conf and outputs.conf settings for a second opinion.&lt;/P&gt;&lt;P&gt;What gave you the impression that Splunk has no rights to send logs?&lt;/P&gt;&lt;P&gt;How are you attempting to send data to the third-party tool?&amp;nbsp; Have you seen &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 14:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/677674#M13658</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-15T14:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF install via Intune</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/683213#M13777</link>
      <description>&lt;P&gt;Hi Steven,&lt;BR /&gt;&lt;BR /&gt;I am trying to push SPLUNK UF to Windows and MAC laptops.&lt;BR /&gt;&lt;BR /&gt;Can you please the steps how you did through Intune. It would be lot helpful&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 10:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/683213#M13777</guid>
      <dc:creator>jai1989</dc:creator>
      <dc:date>2024-04-04T10:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF install via Intune</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/683250#M13778</link>
      <description>&lt;P&gt;Recent versions of the Splunk Universal Forwarder install with a least privileged user that doesn't have the ability to pull Windows event logs by default.&amp;nbsp; This is different from older versions of the UF which worked differently and could pull all logs by default.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not familiar with what you can do with Intune, but do you have the ability to specify command line arguments to run with the deployment? I'm thinking you may need to add something like&amp;nbsp;&lt;SPAN&gt;WINEVENTLOG_SEC_ENABLE=1 (or similar).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Supported_command_line_flags" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.2.1/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller#Supported_command_line_flags&lt;/A&gt;&amp;nbsp;for details along with other supported options.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 13:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-UF-install-via-Intune/m-p/683250#M13778</guid>
      <dc:creator>tkopchak</dc:creator>
      <dc:date>2024-04-04T13:22:40Z</dc:date>
    </item>
  </channel>
</rss>

