Getting Data In

Unable to install universal forwarder on Windows Server 2008

christinmb
Path Finder

Im trying to install the universal forwarder in my windows server 2008 witht the remote windows data option but I keep getting the error:
Splunk Installer was unable to start Splunk Services.
Please make sure you have provided the correct username and/or password, and the user you are trying to run Splunk has the correct privileges. Exitcode='4'

And if I try to use the Splunk web and enter the Active Directory in the data inputs I get this error: Unable to open the selected path. Path doesnt exist or access is denied. and I was wondering if any of you knows why Im getting this errors.

0 Karma
1 Solution

christinmb
Path Finder

Yes, it has admin privileges, thanks anyway. Already fixed it

View solution in original post

0 Karma

christinmb
Path Finder

Yes, it has admin privileges, thanks anyway. Already fixed it

0 Karma

christinmb
Path Finder

The remote event logs collection was because my splunkD service was working as a local account, the issue corrected when I entered a domain account in the "Log on" option in the SplunkD service. The other issue I don't know how to fix it, I was doing the installation for remote windows data and should be local.

0 Karma

rovechkin_splun
Splunk Employee
Splunk Employee

what was the issue then?

0 Karma

rovechkin_splun
Splunk Employee
Splunk Employee

Is your user has admin privileges on the box where UF is installed? here is the link with required privileges:
http://docs.splunk.com/Documentation/Splunk/latest/Installation/InstallonWindows

Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...