<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Receiving this warning: &amp;quot;cannot create &amp;quot;/opt/splunk/var/log/watchdog&amp;quot; in Security</title>
    <link>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394239#M13190</link>
    <description>&lt;P&gt;Hi @dataops &lt;/P&gt;

&lt;P&gt;Thank you for posting your question on Splunk Answers. In order for experts to help you, can you please provide more information in context that resulted in you seeing this error? Were you making changes to the authorize.conf file?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 18:45:05 GMT</pubDate>
    <dc:creator>Anam</dc:creator>
    <dc:date>2019-05-29T18:45:05Z</dc:date>
    <item>
      <title>Receiving this warning: "cannot create "/opt/splunk/var/log/watchdog"</title>
      <link>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394238#M13189</link>
      <description>&lt;P&gt;Why am I receieving this error?&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Warning: cannot create "/opt/splunk/var/log/watchdog"&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 29 May 2019 16:59:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394238#M13189</guid>
      <dc:creator>dataops</dc:creator>
      <dc:date>2019-05-29T16:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving this warning: "cannot create "/opt/splunk/var/log/watchdog"</title>
      <link>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394239#M13190</link>
      <description>&lt;P&gt;Hi @dataops &lt;/P&gt;

&lt;P&gt;Thank you for posting your question on Splunk Answers. In order for experts to help you, can you please provide more information in context that resulted in you seeing this error? Were you making changes to the authorize.conf file?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 18:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394239#M13190</guid>
      <dc:creator>Anam</dc:creator>
      <dc:date>2019-05-29T18:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving this warning: "cannot create "/opt/splunk/var/log/watchdog"</title>
      <link>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394240#M13191</link>
      <description>&lt;P&gt;This can happen if Splunk is run as root and then run as a non-root user without changing the ownership of all files in /opt/splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 19:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394240#M13191</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-29T19:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving this warning: "cannot create "/opt/splunk/var/log/watchdog"</title>
      <link>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394241#M13192</link>
      <description>&lt;P&gt;Agree with Rich, I've seen this behavior in the very same circumstances.&lt;/P&gt;

&lt;P&gt;chown the pid file to the user running splunk.&lt;BR /&gt;
e.g.&lt;BR /&gt;
    chown splunk:splunk /opt/splunk/var/run/splunk/splunkd.pid&lt;BR /&gt;
    cycle splunk&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 14:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Receiving-this-warning-quot-cannot-create-quot-opt-splunk-var/m-p/394241#M13192</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-05-30T14:04:16Z</dc:date>
    </item>
  </channel>
</rss>

