Archive

Running Splunk Forwarder on domain controller - limited privileges

New Member

I've set up the service account using the guidelines here:

=https=://www.splunk.com/blog/2013/04/15/enabling-splunk-as-a-windows-domain-user-with-group-policy.html

With the exception of "Act as part of the operating system" because this basically makes the account a domain admin.

However, I'm still getting a ton of these errors in the splunkd.log:

ERROR ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"" splunk-netmon - NetmonEvent::GetUserInfo: Warning LsaGetLogonSessionData failed with : 0xc0000022

Any suggestions on what permission I need to assign explicitly to overcome this?

Thanks!

0 Karma

SplunkTrust
SplunkTrust

From everything I found online about this, it seems to actually require local Administrator permissions...

0 Karma