Getting Data In

Can't determine universal forwarder service account

sdewar83
Path Finder

Hi,

I've inherited a poorly documented splunk deployment that seems to have been misconfigured. the universal forwarder service isnt starting on workstations due to a logon issue. Either the password is wrong or the account it is configured with is wrong.

Is there a way to determine what account is the correct account/which account the deployment server is expecting the UF to use?

Many thanks in advance.

Labels (1)
0 Karma

kappalkamal
New Member

Please check the owner of the file deploymentclient.conf which was essentially used to poll the server.
Please let me know what you found.

0 Karma
Get Updates on the Splunk Community!

Alpha Launch: AI-Assisted Auto-Schematization for CIM

Streamlining Data Onboarding: Announcing the Alpha Release of AI-Assisted Auto-Schematization For many Splunk ...

Enterprise Security(ES) Essentials or Premier? Let's discuss Splunk ES Editions on ...

  Hi everyone, Last year at .conf25, we shared something exciting: Splunk Enterprise Security is evolving ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 5

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...