Getting Data In

Splunk Universal Forwarder 6.5.3 installed on Windows 10 workstations stop

molinarf
Communicator

I am running Splunk Enterprise on a Windows Server 2012 R2 and have installed both the Splunk Universal Forwarder 6.5.3 and 6.6.1on Windows 10 workstations. I have noticed that after about a week after being installed, the SplunkForwarder Service stops. When I try to start the service, it says that it cannot start because of a logon problem. I found that I have to open the service properties and re-enter the password for the account that it uses. Once I enter the password, I am able to start the service. I have noticed that this happens on a few workstations and sometimes when it is installed on a server. I installed the universal forwarder with using a domain service account. Any ideas? I have chosen to uninstall the UF to see if there was a problem with installation, but I have found that it still occurs.

0 Karma
1 Solution

molinarf
Communicator

I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.

View solution in original post

0 Karma

molinarf
Communicator

I found the fix to the problem. The universal forwarder service was using a domain account. I changed it to using the local admin account for Splunk and it has not had any problems. The best solution is to install using the domain account,then after the universal forwarder is installed change it to use the local Splunk admin account.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...