Getting Data In

Splunk Universal Forwarder 6.5.3 installed on Windows 10 workstations stop

molinarf
Communicator

I am running Splunk Enterprise on a Windows Server 2012 R2 and have installed both the Splunk Universal Forwarder 6.5.3 and 6.6.1on Windows 10 workstations. I have noticed that after about a week after being installed, the SplunkForwarder Service stops. When I try to start the service, it says that it cannot start because of a logon problem. I found that I have to open the service properties and re-enter the password for the account that it uses. Once I enter the password, I am able to start the service. I have noticed that this happens on a few workstations and sometimes when it is installed on a server. I installed the universal forwarder with using a domain service account. Any ideas? I have chosen to uninstall the UF to see if there was a problem with installation, but I have found that it still occurs.

0 Karma
1 Solution

molinarf
Communicator

I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.

View solution in original post

0 Karma

molinarf
Communicator

I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...