I found this document (https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorActiveDirectory) is require "Splunk Enterprise must run as a domain user".
But I installed splunk enterprise with user "Local System" not "Domain Account".
I should uninstall splunk enterprise and install with user "Domain Account"?
For more reference have a look at this
It depends on what you want to monitor with this instance
If i want to monitor:
- Read Event Logs remotely
- Collect performance counters remotely
- Read network shares for log files
- Access the Active Directory schema, using Active Directory monitoring
It's mean i don't need to reinstall splunk enterprise. I just install universal forwarder by use domain account right?