Getting Data In

Splunk Universal Forwarder 6.5.3 installed on Windows 10 workstations stop

molinarf
Communicator

I am running Splunk Enterprise on a Windows Server 2012 R2 and have installed both the Splunk Universal Forwarder 6.5.3 and 6.6.1on Windows 10 workstations. I have noticed that after about a week after being installed, the SplunkForwarder Service stops. When I try to start the service, it says that it cannot start because of a logon problem. I found that I have to open the service properties and re-enter the password for the account that it uses. Once I enter the password, I am able to start the service. I have noticed that this happens on a few workstations and sometimes when it is installed on a server. I installed the universal forwarder with using a domain service account. Any ideas? I have chosen to uninstall the UF to see if there was a problem with installation, but I have found that it still occurs.

0 Karma
1 Solution

molinarf
Communicator

I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.

View solution in original post

0 Karma

molinarf
Communicator

I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...