Installation

Protecting UF from stopping and Uninstallation

jg91
Path Finder

Is there any solution to protect UF from stopping or uninstalling by users on endpoints? For example, most Antivirus agents are password protected and on uninstallation, users must provide the password, I'm looking for this kind of solution.
Thank you.

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jg91,

as described at https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/InstallaWindowsuniversalforwarderfro... you can define an user to install or modify or uninstalla an UF; I didn't tried to uninstalla an UF without this account but I think that the first protection is to have an alert on your Splunk that fires if an UF stops to send logs.

This alert is already available on the Monitoring Console.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...