<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk cannot read messages logs in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100016#M3250</link>
    <description>&lt;P&gt;Grijhwani, &lt;/P&gt;

&lt;P&gt;Only three questions and yet 29 answers.  you are my hero!!!&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jul 2013 20:20:03 GMT</pubDate>
    <dc:creator>hartfoml</dc:creator>
    <dc:date>2013-07-18T20:20:03Z</dc:date>
    <item>
      <title>Splunk cannot read messages logs</title>
      <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100011#M3245</link>
      <description>&lt;P&gt;I have my indexer and search-head installed on RHES and splunkd is not running as root. I can see that the /var/log/messages and other logs are not accessible by the user that is running splunkd.  I would like to collect system logs from my indexers and search-head without giving the splunkd Damon root access. &lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 18:13:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100011#M3245</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-07-18T18:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot read messages logs</title>
      <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100012#M3246</link>
      <description>&lt;P&gt;i don't think splunk needs root access to read logs. If you are using monitor stanza it should read it..&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 18:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100012#M3246</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-07-18T18:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot read messages logs</title>
      <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100013#M3247</link>
      <description>&lt;P&gt;Disagree with previous comment - generally permissions are set so that non-administrative users cannot read most stuff in /var/log.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 18:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100013#M3247</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-07-18T18:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot read messages logs</title>
      <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100014#M3248</link>
      <description>&lt;P&gt;Adding splunk to the syslog group will most likely give it access to your principal system logs, but not everything.  Another option is to make the logs world-readable.  A third option is to create a new group altogether, ensure that all your logs are written under and readable by that group, and add the splunk user to this group instead.&lt;/P&gt;

&lt;P&gt;Finally, to help you with all your syslog configuration needs you could install syslog-ng, which is a highly flexible replacement for the stock syslogd service, which allows vastly greater control over the output files created by syslog.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 19:58:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100014#M3248</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2013-07-18T19:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot read messages logs</title>
      <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100015#M3249</link>
      <description>&lt;P&gt;Thanks much&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 20:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100015#M3249</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-07-18T20:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk cannot read messages logs</title>
      <link>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100016#M3250</link>
      <description>&lt;P&gt;Grijhwani, &lt;/P&gt;

&lt;P&gt;Only three questions and yet 29 answers.  you are my hero!!!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 20:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-cannot-read-messages-logs/m-p/100016#M3250</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-07-18T20:20:03Z</dc:date>
    </item>
  </channel>
</rss>

