Getting Data In

Why can't I start the Splunk Forwarder on a local computer? (Error 1069, login failure)

brucelloyd1
Engager

Splunk Version 6.2.9.276372

Windows could not start the SplunkForwarder service on local computer. Error 1069: The service did not start due to a logon failure.

0 Karma

ddrillic
Ultra Champion

Similar issue at Error 1069 when starting splunkd using domain account

@ttchorz concluded by saying

-- ... I ended up creating a new user with different password and using that account to solve this problem.

0 Karma

amahoski
Explorer

Based on the error that you provided it sounds like the account that you are using to start the splunkd forwarder process most likely does not have the necessary level of permissions to start Splunk as a service. I would suggest checking windows services.msc and either update the account by re-entering the password(if it is incorrect), use an account with a higher permission level, or use a local system account(which is the default if you didn't specify an account when installing).

0 Karma

brucelloyd1
Engager

Well thanks for the suggestions. I just solved my own question.

I solved the Splunk issue which had the following error when I tried to start the SplunkForwarder service.

"Windows could not start the SplunkForwarder service on Local Computer. Error 1069: The service did not start due to a logon failure."

I fixed this error under the SplunkForwarder service properties. Under the Log On tab, I deselected the default radio button for “This account” and its accompanying “tis\splunk” user name and password and selected the radio button for “Local System account” and no box checked for “Allow service to interact with desktop.” Now the SplunkForwarder service starts OK with no errors.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...