Monitoring Splunk

install splunk by user to monitor remote server logs windows os

ips_mandar
Builder

I have data stored on one windows os server now I want to install splunk on another windows server by which I can read remote server logs stored. For this i want to know by which user I will require to install splunk? is it local user or domain user or anything else? since I want to access remote server logs using monitor input and what capability this user should have?
I have gone through https://docs.splunk.com/Documentation/Splunk/7.3.1/Installation/ChoosetheuserSplunkshouldrunas

Tags (1)
0 Karma

mayurr98
Super Champion

Hello

its clearly explained in that doc:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Installation/ChoosetheuserSplunkshouldrunas#The_u...

To do any of the following actions with Splunk Enterprise, you must install it as a domain user:

Read Event Logs remotely
Collect performance counters remotely
Read network shares for log files
Access the Active Directory schema using Active Directory monitoring

To monitor the logs on the remote server, you should install Splunk as Domain User.

0 Karma

ips_mandar
Builder

Thanks @mayurr98
If I have local user which can access remote server stored logs then can I install splunk using that local user?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...