Deployment Architecture

UFW Access to WinEventLogs

tsocyberoperati
Loves-to-Learn Lots

Hello All,

We have a Splunk Universal Forwarder 9.4.0 (then 9.4.3) installed on a Windows 2022 box to which we don't have direct access.
We have deployed some apps and the forwarder manages to send us its splunkd.log and some other monitor inputs but we are not able to get the WinEvents (Applications/System/Security) using the specific stanzas. 

The host is more hardened that usual,  but the Admins managed to configure what they believe are the EventLog permissions, to no avail. Something like this, never happened to us.

We tried updating the agent version and configuring the installation both with LOCAL System permissions and Virtual Account permissions, but still no success.

We don't see any relevant internal info regarding some problem with Permissions or EventLog access. 

- is there any event we should look for on Windows Logs or UFW logs to undertand this problem?
- Is there anything we can activate in the UFW to get more info about this limitation? 

Thank you

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There can be several possible issues probably but since you say that the host has been "additionally hardened" I'd hazard a guess that you have applocker policy preventing unknown/not-whitelisted apps from running. Since the eventlogs are ingested by means of spawning external .exe, if it's not whitelisted, it will fail.

0 Karma

tsocyberoperati
Loves-to-Learn Lots

This is a new installation.
So, no, no Windows Security events onboarded in the past.
Thank you.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @tsocyberoperati 

are you seeing any permission related issues on Splunkd.log 

also check splunk forwarder is running as local user or nt_ user

try running splunk with local user and restart the splunk service 

0 Karma

tsocyberoperati
Loves-to-Learn Lots

Hello

Your questions are answered in the original post.

Thank you

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@tsocyberoperati 

Has this forwarder ever successfully onboarded Windows Security events into Splunk in the past?
 
 
Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...