Hi,
I've inherited a poorly documented splunk deployment that seems to have been misconfigured. the universal forwarder service isnt starting on workstations due to a logon issue. Either the password is wrong or the account it is configured with is wrong.
Is there a way to determine what account is the correct account/which account the deployment server is expecting the UF to use?
Many thanks in advance.
↧