Security

changing Splunk admin account to dmoain service account

rajkumarv
Engager

Hi,

Can any one help, is it possible to change the Splunk admin account which is created in the Splunk (at application level) to domain service account?.
This is required for one of the storage requirement. We have a shared drive (SAN) for Indexer cold storage and that storage drive requires user name and password to authenticate. As per the company policy they will provide access to the shared drive only to the domain service account, however the Splunk instances including Index cluster, Search heads, and master node are installed with username created in Splunk. So are not sure whether the Splunk application will get authenticate to storage drive (SAN shared drive) to store the cold data as per the retention policy. So I would like to know whether we can change the Splunk admin account to domain account for managing splunk.

Tags (1)
0 Karma

lakshman239
Influencer

If you are indexer is running as user 'splunk' that user needs 'read/write' access to your SAN storage for hotwarm and cold buckets. If access cannot be provided to 'splunk' account, you can have a 'service/domain account' created and can be used to run your indexer [ and/or other instances of splunk servers running as 'splunk']. This way, you may be able to work with your policy.

Splunk 'admin' account is a special account for administering splunk instances.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...