Installation

Protecting UF from stopping and Uninstallation

jg91
Path Finder

Is there any solution to protect UF from stopping or uninstalling by users on endpoints? For example, most Antivirus agents are password protected and on uninstallation, users must provide the password, I'm looking for this kind of solution.
Thank you.

Labels (1)
Tags (2)
0 Karma

gcusello
Esteemed Legend

Hi @jg91,

as described at https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/InstallaWindowsuniversalforwarderfro... you can define an user to install or modify or uninstalla an UF; I didn't tried to uninstalla an UF without this account but I think that the first protection is to have an alert on your Splunk that fires if an UF stops to send logs.

This alert is already available on the Monitoring Console.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...