Getting Data In

What are the limitations of installing/running the UF in low privilege mode?

bo055677
New Member

I'm getting push back on installing UFs on domain controllers and I believe installing in low privilege mode is the solution which will meet windows administrators concerns. My only issue is that I haven't been able to find a document that states the exact limitations of running the UF in low privilege mode, other than this article.

https://answers.splunk.com/answers/93998/running-universal-forwarder-with-non-administrator-service-...

Does anyone know if there is a document on what a low privilege UF can't do?

Will this let me run Powershell commands?

0 Karma

nickhills
Ultra Champion

A low privileged user on windows will not be able to access the windows event logs without some additional configuration in your AD audit settings (and potentially a significant amount of pain)

An alternative to this is to run a collector to perform remote log collection, however this is only marginally better, because you have now given a remote system a privileged logon to the domain controllers.

Its only right to point out that this is a limitation of windows, rather than splunk, but my advice is to keep up the fight.
The value (and speed/volume advantage over remote wmi) of a local installed forwarder with sufficient rights is worth it over the headaches in the future.

If remote deployment is a concern (or the ability to do so) I would suggest locally deployed apps (ie no deployment server) over the alternatives - or even better a separate DS just to manage your sensitive deployment clients.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...