All Apps and Add-ons

Should we install forwarders, indexers and search head as local system or domain account for Windows Infrastructure app?

jlhesurance
Engager

If we intend to use the Splunk App for Windows Infrastructure to collect security-related logs (such as Logon/Logoff, GP changes, etc.), should we install the Forwarders, Indexers and Search Head as the Local System account or a domain account? The documentation is pretty clear that the Forwarders should be installed as Local System with no inputs enabled, but it's less clear about the other components.

0 Karma

jbernt_splunk
Splunk Employee
Splunk Employee

Hi there. The forwarders and the account they run as are the only ones that really matter in this case. The Indexers and Search Heads can run on any supported OS, so the Local System account won't be available there anyway. You can run with a domain account, but we recommend Local System if possible unless there is a need to run as a domain user for least privilege.
Thanks!

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...