Getting Data In

Universal forwarder - gMSA - EventID 7000

mhobbelen
New Member

Hello, in ou're environment we've configured the forwarders (Windows, version 6.6.3) to use a gMSA account to run the splunkd service. This account has been granted the correct permissions (as described in the installation documentation).

After an (expected) restart on some systems the service won't startup correctly (Eventid 7000, The SplunkForwarder service failed to start due to the following error:
The service did not start due to a logon failure.)

When this issue arrises, the Test-ADServiceAccount returns a true value. The PrincipalsAllowedToRetrieveManagedPassword properties has been configured with the correct systems that use the gMSA account.

A manual restart will fix this issue. offcourse, this can be trapped within a monitoring solution, or with an action combined to this event, but this is working around an issue imho. What's the best way to troubleshoot/fix this issue.

0 Karma

heikowz
New Member

Hello,
set the starttype of the SplunkForwarder to "auto-delayed" then it works well.
The reason for the error is that the network connection is not complet started during the strat of the SF and it can not verify the gMSA Password with the DomainController.
Regards Heiko

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...