Deployment Architecture

UFW Access to WinEventLogs

tsocyberoperati
Loves-to-Learn Lots

Hello All,

We have a Splunk Universal Forwarder 9.4.0 (then 9.4.3) installed on a Windows 2022 box to which we don't have direct access.
We have deployed some apps and the forwarder manages to send us its splunkd.log and some other monitor inputs but we are not able to get the WinEvents (Applications/System/Security) using the specific stanzas. 

The host is more hardened that usual,  but the Admins managed to configure what they believe are the EventLog permissions, to no avail. Something like this, never happened to us.

We tried updating the agent version and configuring the installation both with LOCAL System permissions and Virtual Account permissions, but still no success.

We don't see any relevant internal info regarding some problem with Permissions or EventLog access. 

- is there any event we should look for on Windows Logs or UFW logs to undertand this problem?
- Is there anything we can activate in the UFW to get more info about this limitation? 

Thank you

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There can be several possible issues probably but since you say that the host has been "additionally hardened" I'd hazard a guess that you have applocker policy preventing unknown/not-whitelisted apps from running. Since the eventlogs are ingested by means of spawning external .exe, if it's not whitelisted, it will fail.

0 Karma

tsocyberoperati
Loves-to-Learn Lots

This is a new installation.
So, no, no Windows Security events onboarded in the past.
Thank you.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @tsocyberoperati 

are you seeing any permission related issues on Splunkd.log 

also check splunk forwarder is running as local user or nt_ user

try running splunk with local user and restart the splunk service 

0 Karma

tsocyberoperati
Loves-to-Learn Lots

Hello

Your questions are answered in the original post.

Thank you

0 Karma

kiran_panchavat
Champion

@tsocyberoperati 

Has this forwarder ever successfully onboarded Windows Security events into Splunk in the past?
 
 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...