<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Starting Splunk Universal Forwarder as non-root in Security</title>
    <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90038#M2957</link>
    <description>&lt;P&gt;I am also having this problem on Solaris 10.&lt;/P&gt;

&lt;P&gt;Ray - did anyone ever get back to you?&lt;/P&gt;

&lt;P&gt;Adam&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2011 18:54:33 GMT</pubDate>
    <dc:creator>adamhmitchell</dc:creator>
    <dc:date>2011-06-14T18:54:33Z</dc:date>
    <item>
      <title>Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90037#M2956</link>
      <description>&lt;P&gt;I've installed Splunk Universal Forwarder 4.2.1 on Solaris 10 (x86 and SPARC), but I can't get them to run as a non-root user.  I followed the instructions at &lt;A href="http://www.splunk.com/base/Documentation/latest/installation/RunSplunkasadifferentornon-rootuser"&gt;http://www.splunk.com/base/Documentation/latest/installation/RunSplunkasadifferentornon-rootuser&lt;/A&gt; to chown $SPLUNK_HOME and set the splunk user privs, but I get the following errors when trying to run Splunk as the splunk user:&lt;/P&gt;

&lt;P&gt;$ id&lt;BR /&gt;&lt;BR /&gt;
uid=40104(splunk) gid=144(splunk)&lt;BR /&gt;
$ /opt/splunkforwarder/bin/splunk start --accept-license&lt;/P&gt;

&lt;P&gt;This appears to be your first time running this version of Splunk.&lt;BR /&gt;
terminate called after throwing an instance of 'ConfPathHasNoWriter'&lt;BR /&gt;
  what():  Could not find writer for: /nobody/system/server/sslConfig [1] [/opt/splunkforwarder/etc]&lt;BR /&gt;
Abort - core dumped&lt;/P&gt;

&lt;P&gt;Splunk&amp;gt; Finding your faults, just like mom.&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/lib/splunk&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/lib/splunk/appserver/i18n&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/lib/splunk/appserver/modules/static/css&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/run/splunk&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/run/splunk/upload&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/spool/splunk&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/spool/dirmoncache&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/lib/splunk/authDb&lt;BR /&gt;
        Creating: /opt/splunkforwarder/var/lib/splunk/hashDb&lt;BR /&gt;
New certs have been generated in '/opt/splunkforwarder/etc/auth'.&lt;BR /&gt;
terminate called after throwing an instance of 'ConfPathHasNoWriter'&lt;BR /&gt;
  what():  Could not find writer for: /nobody/system/server/sslConfig [1] [/opt/splunkforwarder/etc]&lt;BR /&gt;
ERROR: pid 28316 terminated with signal 6 (core dumped)&lt;BR /&gt;
        Checking conf files for typos...&lt;BR /&gt;
terminate called after throwing an instance of 'ConfPathHasNoWriter'&lt;BR /&gt;
  what():  Could not find writer for: /nobody/system/server/sslConfig [1] [/opt/splunkforwarder/etc]&lt;BR /&gt;
ERROR: pid 28317 terminated with signal 6 (core dumped)&lt;BR /&gt;
There might be typos in your conf files. For more information, run 'splunk btool check --debug'&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Starting splunk server daemon (splunkd)... &lt;BR /&gt;
terminate called after throwing an instance of 'ConfPathHasNoWriter'&lt;BR /&gt;
  what():  Could not find writer for: /nobody/system/server/general [1] [/opt/splunkforwarder/etc]&lt;BR /&gt;
ERROR: pid 28325 terminated with signal 6 (core dumped)&lt;/P&gt;

&lt;P&gt;Timed out waiting for splunkd to start.&lt;/P&gt;

&lt;P&gt;Any ideas?  I didn't have this problem when trying on an Ubuntu server with Splunk Universal Forwarder 4.2.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Ray&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2011 16:17:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90037#M2956</guid>
      <dc:creator>leeraym</dc:creator>
      <dc:date>2011-04-27T16:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90038#M2957</link>
      <description>&lt;P&gt;I am also having this problem on Solaris 10.&lt;/P&gt;

&lt;P&gt;Ray - did anyone ever get back to you?&lt;/P&gt;

&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2011 18:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90038#M2957</guid>
      <dc:creator>adamhmitchell</dc:creator>
      <dc:date>2011-06-14T18:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90039#M2958</link>
      <description>&lt;P&gt;Hi Adam,&lt;/P&gt;

&lt;P&gt;No answers so far.  I just let it run as root since it wasn't really a big deal to me.  Would be nice if I could have it run as splunk though.&lt;/P&gt;

&lt;P&gt;Ray&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2011 19:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90039#M2958</guid>
      <dc:creator>leeraym</dc:creator>
      <dc:date>2011-06-14T19:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90040#M2959</link>
      <description>&lt;P&gt;Ray (and all) - I was able to fix this issue today with chmod and still run the agent as 'splunk':&lt;/P&gt;

&lt;P&gt;chmod +w /opt/splunkforwarder/etc/system&lt;/P&gt;

&lt;P&gt;The error was this:&lt;/P&gt;

&lt;P&gt;06-14-2011 16:01:45.163 -0400 ERROR BundlesUtil - Cannot create parent directory: /opt/splunkforwarder/etc/system/metadata: Permission denied&lt;/P&gt;

&lt;P&gt;And the root problem was the permissions on the parent directory.  It was owned by 'splunk' but wasn't writable:&lt;/P&gt;

&lt;P&gt;bash-3.00$ ls -ld /opt/splunkforwarder/etc/system/&lt;BR /&gt;&lt;BR /&gt;
dr-xr-xr-x   7 splunk   splunk         7 Jun 14 14:44 /opt/splunkforwarder/etc/system/&lt;/P&gt;

&lt;P&gt;Hope it works for you too!&lt;/P&gt;

&lt;P&gt;Adam&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 17:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90040#M2959</guid>
      <dc:creator>adamhmitchell</dc:creator>
      <dc:date>2011-06-15T17:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90041#M2960</link>
      <description>&lt;P&gt;Hi leeraym&lt;/P&gt;

&lt;P&gt;I have filed a bug report and this one is currently being processed @splunk. As soon as it's fixed I'll let you know.&lt;BR /&gt;
btw what is your exact release version where this happened?&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2011 05:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90041#M2960</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-08-23T05:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90042#M2961</link>
      <description>&lt;P&gt;This is a known issue (SPL-40616) in the Solaris Universal Forwarder package's setup with incorrect permissions being set.  This was reported in the pkg under 4.2.2 and 4.2.3   &lt;/P&gt;

&lt;P&gt;As indicated above, the workaround is to chmod for &lt;CODE&gt;$SPLUNK_HOME/etc/system&lt;/CODE&gt;&lt;BR /&gt;
from 555 to 755.&lt;/P&gt;

&lt;P&gt;The fix will be addressed in a forthcoming maintenance release.&lt;/P&gt;

&lt;P&gt;Reference to this can also be found in the &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.2.3/ReleaseNotes/Knownissues#Distributed_deployment.2C_forwarder.2C_deployment_server.2C_and_deployment_monitor_issues"&gt;Release Notes Known Issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2011 15:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90042#M2961</guid>
      <dc:creator>Ellen</dc:creator>
      <dc:date>2011-08-31T15:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Starting Splunk Universal Forwarder as non-root</title>
      <link>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90043#M2962</link>
      <description>&lt;P&gt;How to run splunk as non-root if boot-start is enabled?,If this is installed as non-root, how do you enable the boot-start?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 09:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Starting-Splunk-Universal-Forwarder-as-non-root/m-p/90043#M2962</guid>
      <dc:creator>viril</dc:creator>
      <dc:date>2016-09-29T09:37:39Z</dc:date>
    </item>
  </channel>
</rss>

