Running Splunk Forwarder on domain controller - limited privileges

New Member

I've set up the service account using the guidelines here:


With the exception of "Act as part of the operating system" because this basically makes the account a domain admin.

However, I'm still getting a ton of these errors in the splunkd.log:

ERROR ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"" splunk-netmon - NetmonEvent::GetUserInfo: Warning LsaGetLogonSessionData failed with : 0xc0000022

Any suggestions on what permission I need to assign explicitly to overcome this?


0 Karma


From everything I found online about this, it seems to actually require local Administrator permissions...

0 Karma