Monitoring Splunk

install splunk by user to monitor remote server logs windows os

ips_mandar
Builder

I have data stored on one windows os server now I want to install splunk on another windows server by which I can read remote server logs stored. For this i want to know by which user I will require to install splunk? is it local user or domain user or anything else? since I want to access remote server logs using monitor input and what capability this user should have?
I have gone through https://docs.splunk.com/Documentation/Splunk/7.3.1/Installation/ChoosetheuserSplunkshouldrunas

Tags (1)
0 Karma

mayurr98
Super Champion

Hello

its clearly explained in that doc:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Installation/ChoosetheuserSplunkshouldrunas#The_u...

To do any of the following actions with Splunk Enterprise, you must install it as a domain user:

Read Event Logs remotely
Collect performance counters remotely
Read network shares for log files
Access the Active Directory schema using Active Directory monitoring

To monitor the logs on the remote server, you should install Splunk as Domain User.

0 Karma

ips_mandar
Builder

Thanks @mayurr98
If I have local user which can access remote server stored logs then can I install splunk using that local user?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...