- Onboard Cloud Collectors
- Shareable Service Accounts
- Add Accounts for AWS Cloud Collectors
- Add Accounts for Cisco Duo Cloud Collector
- Add Accounts for Google Cloud Collectors
- Add Accounts for Microsoft Cloud Collectors
- Add Accounts for Okta Cloud Collectors
- Add Accounts for Salesforce Cloud Collectors
- Add Accounts for Splunk Cloud Collectors
- Add Accounts for Trend Micro Cloud Collectors
- Add Accounts for Wiz
- Abnormal Security Cloud Collector
- Anomali Cloud Collector
- AWS CloudTrail Cloud Collectors
- AWS CloudWatch Cloud Collector
- AWS CloudWatch Alarms Cloud Collector
- AWS GuardDuty Cloud Collector
- AWS S3 Cloud Collector
- AWS Security Lake Cloud Collector
- AWS SQS Cloud Collector
- Azure Activity Logs Cloud Collector
- Azure Blob Storage Cloud Collector
- Azure Log Analytics Cloud Collector
- Azure Event Hub Cloud Collector
- Azure Storage Analytics Cloud Collector
- Azure Virtual Network Flow Cloud Collector
- Box Cloud Collector
- Broadcom Carbon Black Cloud Collector
- Cato Networks Cloud Collector
- ChatGPT Enterprise Cloud Collector
- Cisco Duo Cloud Collector
- Cisco Meraki Cloud Collector
- Cisco Secure Endpoint Cloud Collector
- Cisco Umbrella Cloud Collector
- Cloudflare Cloud Collector
- Cribl Cloud Collector
- CrowdStrike Cloud Collectors
- Cylance Protect (now Arctic Wolf) Cloud Collector
- DataBahn Cloud Collector
- Dropbox Cloud Collector
- GCP Cloud Logging Cloud Collector
- GCP Pub/Sub Cloud Collector
- GCP Security Command Center Cloud Collector
- Gemini Enterprise Cloud Collector
- GitHub Cloud Collector
- Gmail BigQuery Cloud Collector
- Google Workspace Cloud Collector
- Google Security Operations Cloud Collector
- LastPass Cloud Collector
- Microsoft Copilot Integration
- Microsoft Defender XDR (via Azure Event Hub) Cloud Collector
- Microsoft Entra ID Context Cloud Collector
- Microsoft Entra ID Logs Cloud Collector
- Microsoft 365 Exchange Admin Reports Cloud Collector
- Supported Sources from Microsoft 365 Exchange Admin Reports
- Migrate to the Microsoft 365 Exchange Admin Reports Cloud Collector
- Prerequisites to Configure the Microsoft 365 Exchange Admin Reports Cloud Collector
- Configure the Microsoft 365 Exchange Admin Reports Cloud Collector
- Troubleshooting the Microsoft 365 Exchange Admin Reports Cloud Collector
- Recover Stopped Log Ingestion for Microsoft 365 Exchange Admin Reports Cloud Collector
- Microsoft 365 Management Activity Cloud Collector
- Microsoft Security Alerts Cloud Collector
- Microsoft Sentinel (via Event Hub) Cloud Collector
- Mimecast Cloud Collector
- Mimecast Incydr Cloud Collector
- Netskope Alerts Cloud Collector
- Netskope Events Cloud Collector
- Okta Cloud Collector
- Okta Context Cloud Collector
- OpenAI Cloud Collector
- Palo Alto Networks Cortex Data Lake Cloud Collector
- Palo Alto Networks XDR Cloud Collector
- Phishing Email Inbox Cloud Collector
- PingOne Identity Cloud Collector
- Progress ShareFile Cloud Collector
- Proofpoint On-Demand Cloud Collector
- Proofpoint Targeted Attack Protection Cloud Collector
- Qualys Cloud Collector
- Recorded Future Cloud Collector
- Recorded Future Context Cloud Collector
- Rest API Cloud Collector
- S2W Threat Intelligence Cloud Collector
- Salesforce Cloud Collector
- Salesforce EventLog Cloud Collector
- SentinelOne Alerts Cloud Collector
- SentinelOne Cloud Funnel Cloud Collector
- SentinelOne Threats Cloud Collector
- SentinelOne Cloud Collector
- ServiceNow Cloud Collector
- Slack Cloud Collector
- Snowflake Cloud Collector
- Sophos Central Cloud Collector
- Splunk Cloud Collector
- STIX/TAXII Cloud Collector
- Symantec Endpoint Security Cloud Collector
- Tenable Cloud Collector
- Trend Vision One Cloud Collector
- Trellix Endpoint Security Cloud Collector
- Vectra Cloud Collector
- Webhook Cloud Collectors
- Wiz API Cloud Collector
- Workday Cloud Collector
- Zoom Cloud Collector
- Zscaler ZIA Cloud Collector
- Shareable Service Accounts
Reset Password for Splunk Account for Cloud Collectors
Active background jobs continue running even after you stop cloud collectors from the user interface. If you reset the password while these jobs run with old credentials, the system will lock the account and stop data collection. Before resetting your password, understand these critical Cloud Collectors behaviors:
Background Processing: Cloud Collectors process data through backend jobs that may continue running after collectors are stopped via the user interface.
Cached Credentials: Active background jobs retain and use old password data.
Account Lockout: Repeated authentication failures automatically lock the Splunk account.
Authentication Failures: Resetting Splunk account passwords during active jobs causes repeated authentication failures.
Data Disruption: Multiple failed authentication attempts may trigger a Splunk account lockout. These lockouts immediately stop all active data collection.
Use the following best practices when resetting the Splunk account password used by Cloud Collectors. These steps prevent authentication failures and unexpected account lockouts in high-volume production environments.
Option 1 (Recommended): Use a New Splunk Account
Option 2: Reset Password of Existing Account (Planned Downtime Required)
Use a New Splunk Account
This approach is recommended for high-volume production environments. Following are the benefits of this approach.
Zero Lockout Risk: Eliminates account lockouts.
Continuous Data Ingestion: Maintains uninterrupted, ongoing data ingestion.
Maximum Safety: Provides the safest approach for live production systems.
Use the following steps to use new Splunk account credentials.
Create a new Splunk service account.
Update the cloud collector configuration to use the new account credentials.
Start the Cloud Collectors and confirm that data ingestion is working correctly.
Allow sufficient time (for example, several hours) for any remaining backend jobs using the old account to complete.
Disable or remove the old Splunk account after confirming stable operation.
Reset Password of Existing Account
Use this approach only when creating a new account is not possible.
Stop all Splunk Cloud Collectors from the user interface (UI).
Ensure that you do not reset the password immediately after stopping collectors.
Wait for background jobs to finish before updating your password. This prevents running processes from failing by attempting to log in with your old credentials.
As a general rule, wait at least twice the duration of your typical job execution or data ingestion cycle.
Test Environments (low‑volume): 30–60 minutes.
Production Environments (high‑volume): 90 minutes or more.
(Optional) Check the Last Log Received indicator as a reference. Note that this indicator does not guarantee completion of all background jobs.
Reset the Splunk account password.
Update the Cloud Collector configuration with the new password.
Restart Cloud Collectors and monitor data ingestion.
Note
Background jobs may continue authenticating with your old password. Resetting your password too soon can cause authentication issues and may lock your account.
Practices to Avoid
Avoid the following actions to prevent disruption and account lockouts.
Immediate Password Resets: Avoid resetting the Splunk account password right after stopping the cloud collectors.
Background Process Verification: Do not assume a 'Stopped' status on the ser interface means all background processing has finished. Verify that all background processing is complete.
Single Collector Testing: Never test password changes on a single collector in high-volume environments, as a lockout impacts all collectors that share the same account.
Summary of Recommendations
Select the appropriate action based on your specific environment.
Production and High-Volume Environments: Create and switch to a new account to maintain stability.
Minimal Downtime Requirements: Create a new account first, then decommission the old account later.
Low-Volume or Test Environments: Proceed with a standard password reset after waiting for the recommended time.
Splunk Account Lockout Recovery
Use the following steps to recover safely if repeated authentication failures lock the Splunk account used by cloud collectors.
Stop cloud collectors: Stop all cloud collectors from the user interface to block new collector jobs.
Delay Password Changes: Avoid an immediate password reset, which prolongs the lockout.
Wait for Retries: Wait until collector retry cycles are exhausted before taking further action. Pause up to 90 minutes for high-volume environments to let background retries finish.
Verify Unlock: Confirm on the Splunk side that the account is no longer locked.
Select a recovery path.
Preferred: Create a new Splunk service account and update Cloud Collectors to use the new credentials.
Alternative: Reset the password of the existing account only after backend retries have completed.
Restart Collectors and Monitor Ingestion: Restart cloud collectors and verify data ingestion before decommissioning old credentials.
Note
Account lockouts affect all collectors sharing that account; therefore, creating a new service account ensures the fastest and safest recovery for production environments.
To avoid service interruptions caused by backend processing behavior, use a new account when updating credentials in production environments.