Installation

Why the ErrorCode 5 when trying to forward Sysmon logs (unable to subscribe)?

pck1983
Explorer

I got the following errors in my Splunk Error Logs:

Init failedunable to subscribe to Windows Event Log channel Microsoft-Windows-Sysmon/Operational: errorCode=5

The UniversalForwarder is installed on a Windows 10 Desktop (not part of a Doamin).

I can see Sysmon logging in the eventlog viewer and I can forward the System and Security logs but not the Sysmon logs. What do I overlook here?

inputs.conf:

 

[WinEventLog://Security]
disabled = 0

[WinEventLog://System]
disabled = 0

[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = 0

 

Labels (2)
Tags (1)
0 Karma

mawni
Engager

Hi  

It was due to the user being configured to run the Splunk forwarder Windows service. It was a local user account without the necessary rights. I changed it to a local system account and the events started to flow in.

 

Thanks,

Awni

gazoscreek
Path Finder

May I ask how you changed the UF to run as System? Is it simply a case of setting SPLUNK_OS_USER in splunk-launch.conf like it would be on a linux host?

ie:
SPLUNK_OS_USER=SYSTEM

Thank you, and apologies if this is a really lame question.

0 Karma

soberocean
Engager

Hey,

I had the same issue and I fixed it by changing the user through Services:

soberocean_0-1729782932885.png

 

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...