Getting Data In

Why can't I start the Splunk Forwarder on a local computer? (Error 1069, login failure)

brucelloyd1
Engager

Splunk Version 6.2.9.276372

Windows could not start the SplunkForwarder service on local computer. Error 1069: The service did not start due to a logon failure.

0 Karma

ddrillic
Ultra Champion

Similar issue at Error 1069 when starting splunkd using domain account

@ttchorz concluded by saying

-- ... I ended up creating a new user with different password and using that account to solve this problem.

0 Karma

amahoski
Explorer

Based on the error that you provided it sounds like the account that you are using to start the splunkd forwarder process most likely does not have the necessary level of permissions to start Splunk as a service. I would suggest checking windows services.msc and either update the account by re-entering the password(if it is incorrect), use an account with a higher permission level, or use a local system account(which is the default if you didn't specify an account when installing).

0 Karma

brucelloyd1
Engager

Well thanks for the suggestions. I just solved my own question.

I solved the Splunk issue which had the following error when I tried to start the SplunkForwarder service.

"Windows could not start the SplunkForwarder service on Local Computer. Error 1069: The service did not start due to a logon failure."

I fixed this error under the SplunkForwarder service properties. Under the Log On tab, I deselected the default radio button for “This account” and its accompanying “tis\splunk” user name and password and selected the radio button for “Local System account” and no box checked for “Allow service to interact with desktop.” Now the SplunkForwarder service starts OK with no errors.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...