Getting Data In

Why can't I start the Splunk Forwarder on a local computer? (Error 1069, login failure)

brucelloyd1
Engager

Splunk Version 6.2.9.276372

Windows could not start the SplunkForwarder service on local computer. Error 1069: The service did not start due to a logon failure.

0 Karma

ddrillic
Ultra Champion

Similar issue at Error 1069 when starting splunkd using domain account

@ttchorz concluded by saying

-- ... I ended up creating a new user with different password and using that account to solve this problem.

0 Karma

amahoski
Explorer

Based on the error that you provided it sounds like the account that you are using to start the splunkd forwarder process most likely does not have the necessary level of permissions to start Splunk as a service. I would suggest checking windows services.msc and either update the account by re-entering the password(if it is incorrect), use an account with a higher permission level, or use a local system account(which is the default if you didn't specify an account when installing).

0 Karma

brucelloyd1
Engager

Well thanks for the suggestions. I just solved my own question.

I solved the Splunk issue which had the following error when I tried to start the SplunkForwarder service.

"Windows could not start the SplunkForwarder service on Local Computer. Error 1069: The service did not start due to a logon failure."

I fixed this error under the SplunkForwarder service properties. Under the Log On tab, I deselected the default radio button for “This account” and its accompanying “tis\splunk” user name and password and selected the radio button for “Local System account” and no box checked for “Allow service to interact with desktop.” Now the SplunkForwarder service starts OK with no errors.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...