Getting Data In

Can I create a minimum capability user role on a Linux Universal Forwarder so events can be accepted and forwarded to the indexer?

wardallen
Path Finder

I have a Linux Universal Forwarder that will be receiving events via the REST interface's simple receiver.

https://linuxUF:8089/services/receivers/simple?host=xxx&source=xxx&index=xxx&sourcetype=xxx&check-in...

Can I set up a minimum capability role (i.e. not admin) user on the UF so that events can be accepted and forwarded to the indexer? I'd like to create a local user on the UF, and give that user this role.

0 Karma

MuS
Legend

Hi wardallen,

I don't think this is possible using an universal forwarder, but you can try and report back 😉
If it is not working, use a so called heavy forwarder and create the user on it.

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...