Splunk Enterprise

Running Splunk Forwarder on domain controller - limited privileges

fnbrown
New Member

I've set up the service account using the guidelines here:

=https=://www.splunk.com/blog/2013/04/15/enabling-splunk-as-a-windows-domain-user-with-group-policy.html

With the exception of "Act as part of the operating system" because this basically makes the account a domain admin.

However, I'm still getting a ton of these errors in the splunkd.log:

ERROR ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"" splunk-netmon - NetmonEvent::GetUserInfo: Warning LsaGetLogonSessionData failed with : 0xc0000022

Any suggestions on what permission I need to assign explicitly to overcome this?

Thanks!

0 Karma

xpac
SplunkTrust
SplunkTrust

From everything I found online about this, it seems to actually require local Administrator permissions...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...