Getting Data In

Can I create a minimum capability user role on a Linux Universal Forwarder so events can be accepted and forwarded to the indexer?

wardallen
Path Finder

I have a Linux Universal Forwarder that will be receiving events via the REST interface's simple receiver.

https://linuxUF:8089/services/receivers/simple?host=xxx&source=xxx&index=xxx&sourcetype=xxx&check-in...

Can I set up a minimum capability role (i.e. not admin) user on the UF so that events can be accepted and forwarded to the indexer? I'd like to create a local user on the UF, and give that user this role.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi wardallen,

I don't think this is possible using an universal forwarder, but you can try and report back 😉
If it is not working, use a so called heavy forwarder and create the user on it.

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...