Hi
I found this document (https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorActiveDirectory) is require "Splunk Enterprise must run as a domain user".
But I installed splunk enterprise with user "Local System" not "Domain Account".
I should uninstall splunk enterprise and install with user "Domain Account"?
Thanks
Hi
For more reference have a look at this
https://answers.splunk.com/answers/527728/does-the-windows-active-directory-user-for-splunk.html
https://answers.splunk.com/answers/116800/local-system-account-or-domain-user-account.html
It depends on what you want to monitor with this instance
If i want to monitor:
- Read Event Logs remotely
- Collect performance counters remotely
- Read network shares for log files
- Access the Active Directory schema, using Active Directory monitoring
It's mean i don't need to reinstall splunk enterprise. I just install universal forwarder by use domain account right?
Thanks