Deployment Architecture

When your universal forwarder runs as root, should all of your apps run as root?

campbellj1977
Explorer

If so, does that mean your deployment server should run as root also? It keeps deploying client apps as "splunk"

0 Karma

dflodstrom
Builder

Best practice is to run splunk as a user other than root.

If your universal forwarder is running with root/admin privileges you shouldn't have any issues with communication between it and your indexer.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...