Getting Data In

Unable to install universal forwarder on Windows Server 2008

christinmb
Path Finder

Im trying to install the universal forwarder in my windows server 2008 witht the remote windows data option but I keep getting the error:
Splunk Installer was unable to start Splunk Services.
Please make sure you have provided the correct username and/or password, and the user you are trying to run Splunk has the correct privileges. Exitcode='4'

And if I try to use the Splunk web and enter the Active Directory in the data inputs I get this error: Unable to open the selected path. Path doesnt exist or access is denied. and I was wondering if any of you knows why Im getting this errors.

0 Karma
1 Solution

christinmb
Path Finder

Yes, it has admin privileges, thanks anyway. Already fixed it

View solution in original post

0 Karma

christinmb
Path Finder

Yes, it has admin privileges, thanks anyway. Already fixed it

0 Karma

christinmb
Path Finder

The remote event logs collection was because my splunkD service was working as a local account, the issue corrected when I entered a domain account in the "Log on" option in the SplunkD service. The other issue I don't know how to fix it, I was doing the installation for remote windows data and should be local.

0 Karma

rovechkin_splun
Splunk Employee
Splunk Employee

what was the issue then?

0 Karma

rovechkin_splun
Splunk Employee
Splunk Employee

Is your user has admin privileges on the box where UF is installed? here is the link with required privileges:
http://docs.splunk.com/Documentation/Splunk/latest/Installation/InstallonWindows

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...