Installation

Install universal forwarder Splunk-9.2.0.1-x64 from GPO

trha_
Loves-to-Learn

I am trying to install splunk with GPO. Previously, I installed it locally on the machines with a batch file with additional installation parameters.
Now I use the same batch file with a GPO and I get a system error 1376 "The specified local group does not exist"
Same user works when I install locally.
When I install locally I use domain\username.
The user is used to run the splunk service.

Labels (3)
0 Karma

jho-splunk
Splunk Employee
Splunk Employee

Hi @trha_ ,

Would it be possible to somehow see a copy of this batch file?

Cheers,

 

 - Jo.

0 Karma

Boxswurst
Loves-to-Learn

We have the same problem here. The “Performance Monitor Users” group does not exist on a domain controller. Accordingly, the domain account for the forwarder cannot be added.

0 Karma

trha_
Loves-to-Learn

I am having the issue on Windows clients.

Because the group isn't on Domain Controllers shouldn't splunk install clients anyway?

If I dont use my AD user to run the service I am able to install splunk from GPO. The installer creates a user and put it on NT Service.

The NT Service\splunk-user is not added to any of the required groups I do that manually.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...