Installation

Protecting UF from stopping and Uninstallation

jg91
Path Finder

Is there any solution to protect UF from stopping or uninstalling by users on endpoints? For example, most Antivirus agents are password protected and on uninstallation, users must provide the password, I'm looking for this kind of solution.
Thank you.

Labels (1)
Tags (2)
0 Karma

gcusello
Legend

Hi @jg91,

as described at https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/InstallaWindowsuniversalforwarderfro... you can define an user to install or modify or uninstalla an UF; I didn't tried to uninstalla an UF without this account but I think that the first protection is to have an alert on your Splunk that fires if an UF stops to send logs.

This alert is already available on the Monitoring Console.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...