<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk_TA_nix in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454356#M55878</link>
    <description>&lt;P&gt;In that theme, here's more info that delve into the Windows considerations: &lt;A href="https://answers.splunk.com/answers/716045/what-are-best-practices-for-deploying-the-splunk-a.html"&gt;What are best practices for deploying the Splunk Add-on for Unix and Linux in a distributed environment?&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jan 2019 20:20:53 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2019-01-16T20:20:53Z</dc:date>
    <item>
      <title>Splunk_TA_nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454352#M55874</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;So on a quite a few of our Splunk servers we are running Splunk as a non-root user.  Well we deploy Splunk_TA_nix 6.0.0 to all our Linux clients.  Quite a few of the scripts that get run as part of the TA_nix add-on require root privs to execute properly.  How do I get around this?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
ed&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454352#M55874</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2020-09-29T21:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454353#M55875</link>
      <description>&lt;P&gt;Ultimately, you'll need to make sure the unix ID running Splunk can run the requisite commands on the command line of the unix OS terminal/command prompt without errors.&lt;/P&gt;

&lt;P&gt;Often, this is resolved by having the admin of the OS provide the permissions needed.&lt;/P&gt;

&lt;P&gt;If you end up working on collecting files as well, this post might be of help: &lt;A href="https://answers.splunk.com/answers/710445/which-unix-permissions-are-best-for-monitoring-fil.html"&gt;Which UNIX permissions are best for monitoring files?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 17:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454353#M55875</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-01-03T17:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454354#M55876</link>
      <description>&lt;P&gt;Actually, what commands have root requirement? I'm not seeing any.&lt;/P&gt;

&lt;P&gt;Even though the processes they use might be owned by root, those commands should ultimately have the permissions &lt;CODE&gt;-rwxr-xr-x&lt;/CODE&gt; so group and other users can read and execute. The same is true for the parent directory of those commands.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 18:52:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454354#M55876</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-01-07T18:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454355#M55877</link>
      <description>&lt;P&gt;I'd bet a dollar that the deployment server is Windows based.  Windows based deployers totally foul up the permissions of the TA_nix when they push it.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 18:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454355#M55877</guid>
      <dc:creator>michael_schmidt</dc:creator>
      <dc:date>2019-01-07T18:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_nix</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454356#M55878</link>
      <description>&lt;P&gt;In that theme, here's more info that delve into the Windows considerations: &lt;A href="https://answers.splunk.com/answers/716045/what-are-best-practices-for-deploying-the-splunk-a.html"&gt;What are best practices for deploying the Splunk Add-on for Unix and Linux in a distributed environment?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 20:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-nix/m-p/454356#M55878</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-01-16T20:20:53Z</dc:date>
    </item>
  </channel>
</rss>

