<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder running as Splunk user in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarder-running-as-Splunk-user/m-p/551122#M65586</link>
    <description>&lt;P&gt;You could try giving Splunk access to all .bash_history files using &lt;FONT face="courier new,courier"&gt;setfacl&lt;/FONT&gt;.&amp;nbsp; I don't know if the command has to be repeated when new users are added.&lt;/P&gt;</description>
    <pubDate>Mon, 10 May 2021 18:14:27 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-05-10T18:14:27Z</dc:date>
    <item>
      <title>Forwarder running as Splunk user</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarder-running-as-Splunk-user/m-p/551110#M65582</link>
      <description>&lt;P&gt;My Splunk forwarder is running as a splunk user and not root. What is the best way to grant this user read access to user's .bash_history logs without enforcing sudo? If I am not mistaken, theres no way for us to tell the splunk forwarder to run sudo and supply with its own creds again.&lt;/P&gt;&lt;P&gt;Any guidance will be very appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 16:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarder-running-as-Splunk-user/m-p/551110#M65582</guid>
      <dc:creator>logtastic</dc:creator>
      <dc:date>2021-05-10T16:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder running as Splunk user</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarder-running-as-Splunk-user/m-p/551122#M65586</link>
      <description>&lt;P&gt;You could try giving Splunk access to all .bash_history files using &lt;FONT face="courier new,courier"&gt;setfacl&lt;/FONT&gt;.&amp;nbsp; I don't know if the command has to be repeated when new users are added.&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 18:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Forwarder-running-as-Splunk-user/m-p/551122#M65586</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-10T18:14:27Z</dc:date>
    </item>
  </channel>
</rss>

