Deployment Architecture

UFW Access to WinEventLogs

tsocyberoperati
Loves-to-Learn Lots

Hello All,

We have a Splunk Universal Forwarder 9.4.0 (then 9.4.3) installed on a Windows 2022 box to which we don't have direct access.
We have deployed some apps and the forwarder manages to send us its splunkd.log and some other monitor inputs but we are not able to get the WinEvents (Applications/System/Security) using the specific stanzas. 

The host is more hardened that usual,  but the Admins managed to configure what they believe are the EventLog permissions, to no avail. Something like this, never happened to us.

We tried updating the agent version and configuring the installation both with LOCAL System permissions and Virtual Account permissions, but still no success.

We don't see any relevant internal info regarding some problem with Permissions or EventLog access. 

- is there any event we should look for on Windows Logs or UFW logs to undertand this problem?
- Is there anything we can activate in the UFW to get more info about this limitation? 

Thank you

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There can be several possible issues probably but since you say that the host has been "additionally hardened" I'd hazard a guess that you have applocker policy preventing unknown/not-whitelisted apps from running. Since the eventlogs are ingested by means of spawning external .exe, if it's not whitelisted, it will fail.

0 Karma

tsocyberoperati
Loves-to-Learn Lots

This is a new installation.
So, no, no Windows Security events onboarded in the past.
Thank you.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @tsocyberoperati 

are you seeing any permission related issues on Splunkd.log 

also check splunk forwarder is running as local user or nt_ user

try running splunk with local user and restart the splunk service 

0 Karma

tsocyberoperati
Loves-to-Learn Lots

Hello

Your questions are answered in the original post.

Thank you

0 Karma

kiran_panchavat
Champion

@tsocyberoperati 

Has this forwarder ever successfully onboarded Windows Security events into Splunk in the past?
 
 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...