My question has to do with the splunk account that was deleted from a univeral forwarder. The system is a Red Hat 6 server that is setup as a univeral forwarder to our splunk indexers. The account was deleted from the system by an administrator, then restored. The account was restored with the same UID's and GID's previously set. The logs never stopped going to the indexers as the service was not stopped or restarted. Is the restoration of the splunk account with UID's and GID's sufficient to prevent any failures or reloading of the univeral forwarder.
... View more