Installation

Splunk Enterprise installation, Local or Domain- Are there big differences and can local admin be linked with AD?

yohhpark
Path Finder

From the installation option, there is one section where I can choose from Local or domain Account. Some how installation using Domain wasn't working, so I used Local account to install. 

1. Are there a BIG difference between those two installation? I understand that we can authenticate with LDAP on the Splunk Web, so does it mean local/domain won't matter that much?

2. We have created the local admin account, can this be linked with AD and uploaded under specified DC groups?

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @yohhpark,

I never saw an installation as Domain admin grants, always as Local!

In addition, you could also use another role but in this case you have to manage grant accesses to all resources, instead local  admins is ok.

Ciao.

Giuseppe

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I've never installed "full" Splunk installation on Windows, just UF but.

1) For internal Splunk server workings, there should be no difference.

2) If you want to do local ingestion (like reading local eventlogs) Local System will make it easier to read those

3) You might want to perform some actions or run some modular inputs that could use elevated privileges. Again - Local System would be easier to work with.

4) In general - Local System is an account with a very wide set of privileges and should not be used unless absolutely necessary.

5) If you want to perform some ingestion "across your AD" (like reading other computers' EventLogs via WMI or reading files from shares on other servers), you need AD account. Otherwise you won't be able to authenticate to remote resources.

So it's all just a matter of your actual needs and risk assessment. I'd just say that typically for such cases you should use managed service account in your AD.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @yohhpark,

I never saw an installation as Domain admin grants, always as Local!

In addition, you could also use another role but in this case you have to manage grant accesses to all resources, instead local  admins is ok.

Ciao.

Giuseppe

0 Karma

yohhpark
Path Finder

Thank you

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @yohhpark,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

yohhpark
Path Finder

hi Legend,

 

I have posted another questions. would you be able to take a look?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @yohhpark,

which one?

anyway, if i didn't Answer is because I haven't an answer!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...