Installation

Why the ErrorCode 5 when trying to forward Sysmon logs (unable to subscribe)?

pck1983
Explorer

I got the following errors in my Splunk Error Logs:

Init failedunable to subscribe to Windows Event Log channel Microsoft-Windows-Sysmon/Operational: errorCode=5

The UniversalForwarder is installed on a Windows 10 Desktop (not part of a Doamin).

I can see Sysmon logging in the eventlog viewer and I can forward the System and Security logs but not the Sysmon logs. What do I overlook here?

inputs.conf:

 

[WinEventLog://Security]
disabled = 0

[WinEventLog://System]
disabled = 0

[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = 0

 

Labels (2)
Tags (1)
0 Karma

mawni
Engager

Hi  

It was due to the user being configured to run the Splunk forwarder Windows service. It was a local user account without the necessary rights. I changed it to a local system account and the events started to flow in.

 

Thanks,

Awni

gazoscreek
Path Finder

May I ask how you changed the UF to run as System? Is it simply a case of setting SPLUNK_OS_USER in splunk-launch.conf like it would be on a linux host?

ie:
SPLUNK_OS_USER=SYSTEM

Thank you, and apologies if this is a really lame question.

0 Karma

soberocean
Engager

Hey,

I had the same issue and I fixed it by changing the user through Services:

soberocean_0-1729782932885.png

 

 

Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...