I am running Splunk Enterprise on a Windows Server 2012 R2 and have installed both the Splunk Universal Forwarder 6.5.3 and 6.6.1on Windows 10 workstations. I have noticed that after about a week after being installed, the SplunkForwarder Service stops. When I try to start the service, it says that it cannot start because of a logon problem. I found that I have to open the service properties and re-enter the password for the account that it uses. Once I enter the password, I am able to start the service. I have noticed that this happens on a few workstations and sometimes when it is installed on a server. I installed the universal forwarder with using a domain service account. Any ideas? I have chosen to uninstall the UF to see if there was a problem with installation, but I have found that it still occurs.
I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.
I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.