Getting Data In

Can you help me with my Splunk Universal Forwarder starting problem?

johann2017
Explorer

Hello. I am troubleshooting a universal forwarder installed on a Windows system. I noticed that the SplunkForwarder service only starts if the "Log On As" user for the service has administrator rights on the system. How can I grant permissions to start the service without it needing admin rights on the system?

0 Karma

FrankVl
Ultra Champion

The main question is: how did you install the UF? If it was installed using a privileged account and you are now trying to start it with a non-privileged account, it will probably fail, as that account does not have the required permissions on the install dir.

It is possible to run Splunk under a non-admin user, but then it also needs to be installed as such I think (or you need to manually update the permissions on the Splunk install dir such that the account you want to use has access to that).

See also: http://docs.splunk.com/Documentation/Forwarder/7.2.1/Forwarder/InstallaWindowsuniversalforwarderfrom...

0 Karma

sahiltcs
Path Finder

Always you need to run service with administrator account and cmd prompt Without admin rights you can't run services, If you don't have admin rights you need to ask user to start the services who have admin rights.

0 Karma

joebisesi
Path Finder

On all of our systems that have the UF installed, they are running as Local System Account. They do not and should not be run using the Administrator Account.

0 Karma

sahiltcs
Path Finder

Agree with your comments but if we have Universal forwarder installed on another system and we don't have permissions to start the services then we need to ask user to start the services who have admin rights.

0 Karma

joebisesi
Path Finder

Are you running as a specific user, or as the Local System Account? Generally speaking, I believe it should use the Local System Account.
Another note, I have always tried starting the service from an Administrator cmd prompt. Not from the Services window.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...