<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Attempting to revert the SPLUNK_HOME ownership in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650882#M16852</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239959"&gt;@Skeer-Jamf&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;this is known issue, as long as splunkforwarder owned by correct user and working as expected, it wont cause any issue, refercene to known issues of UF&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/ReleaseNotes/Knownissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/ReleaseNotes/Knownissues&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SanjayReddy_0-1689619301268.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26305iCD1BE1B4E5C86FEE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SanjayReddy_0-1689619301268.png" alt="SanjayReddy_0-1689619301268.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----&lt;BR /&gt;Regards,&lt;BR /&gt;Sanjay Reddy&lt;/P&gt;&lt;P&gt;----&lt;BR /&gt;If this reply helps you, Karma would be appreciated.&lt;BR /&gt;&lt;SPAN&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2023 18:43:42 GMT</pubDate>
    <dc:creator>SanjayReddy</dc:creator>
    <dc:date>2023-07-17T18:43:42Z</dc:date>
    <item>
      <title>Attempting to revert the SPLUNK_HOME ownership?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650875#M16851</link>
      <description>&lt;P&gt;This happens regardless of it I am installing fresh or upgrading to version 9.1.0.1an existing install. Every action that involves the splunk binary prepends all output with:&lt;/P&gt;
&lt;P&gt;Warning: Attempting to revert the SPLUNK_HOME ownership&lt;BR /&gt;Warning: Executing "chown -R splunkfwd /opt/splunkforwarder"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried manually running that, as Root! And it still persists even though now the contents under /opt/splunkforwarder are owned by splunkfwd recursively!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 15:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650875#M16851</guid>
      <dc:creator>Skeer-Jamf</dc:creator>
      <dc:date>2023-07-18T15:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650882#M16852</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239959"&gt;@Skeer-Jamf&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;this is known issue, as long as splunkforwarder owned by correct user and working as expected, it wont cause any issue, refercene to known issues of UF&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/ReleaseNotes/Knownissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/ReleaseNotes/Knownissues&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SanjayReddy_0-1689619301268.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26305iCD1BE1B4E5C86FEE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SanjayReddy_0-1689619301268.png" alt="SanjayReddy_0-1689619301268.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----&lt;BR /&gt;Regards,&lt;BR /&gt;Sanjay Reddy&lt;/P&gt;&lt;P&gt;----&lt;BR /&gt;If this reply helps you, Karma would be appreciated.&lt;BR /&gt;&lt;SPAN&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 18:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650882#M16852</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2023-07-17T18:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650886#M16853</link>
      <description>&lt;P&gt;Thank you Sanjay,&amp;nbsp; so yet another known issue huh? Upgrading/installing version 9 has a few it seems.&lt;/P&gt;&lt;P&gt;So, being as though I'm sure this is low priority is there any ETA on it at all? I have automation that handles the installing of the UF. Now when checking the returns/results of a service restart I need to make sure to include bits to ensure the 'Warning' generated doesn't cause me problems.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 19:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/650886#M16853</guid>
      <dc:creator>Skeer-Jamf</dc:creator>
      <dc:date>2023-07-17T19:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/668490#M17859</link>
      <description>&lt;P&gt;I want to point out that these two warnings are breaking my jobs because on some machines I am using the splunkforwarder CLI to run query on the splunk cluster and export the result to files.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Search/ExportdatausingCLI" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Search/ExportdatausingCLI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;These two extra warning lines were now written to the export files as well.&lt;/P&gt;&lt;P&gt;I think it is ok for the CLI to print warnings, but the splunk CLI should follow the best practice and write these warnings to the stderr.&amp;nbsp; But it's writing them to the stdout, so that we can't use the standard practice of " 2&amp;gt; err.txt 1&amp;gt; export.csv" to handle warnings.&lt;/P&gt;&lt;P&gt;Now I have to add these to ALL the script files which are running the splunkforwarder CLI, which is pretty ugly:&lt;BR /&gt;" | grep -vi "warning:" &amp;gt; export.csv"&lt;/P&gt;&lt;P&gt;Wish there is a flag to disable warnings, or the splunkforwarder CLI should at least write them to stderr instead of stdout.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 02:40:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/668490#M17859</guid>
      <dc:creator>patng_nw</dc:creator>
      <dc:date>2023-11-14T02:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/676799#M18614</link>
      <description>&lt;P&gt;It is a breaking issue as I cannot run btool on my forwarders that are throwing this message.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 03:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/676799#M18614</guid>
      <dc:creator>jfrench</dc:creator>
      <dc:date>2024-02-07T03:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/749078#M22538</link>
      <description>&lt;P&gt;btool is a own program in $SPLUNK_HOME/bin&lt;BR /&gt;It is a bit more tricky to use because you have to be in splunk env.&lt;BR /&gt;&lt;BR /&gt;I tested successful following procedure on UF 9.2.2&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;. /opt/splunkforwarder/bin/setSplunkEnv
btool inputs list&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;without sourcing the Splunk Env you get missing libraries error:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunkforwarder/bin/btool inputs list
/opt/splunkforwarder/bin/splunkd: error while loading shared libraries: libmongoc-1.0.so.0: cannot open shared object file: No such file or directory&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 07:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/749078#M22538</guid>
      <dc:creator>SierraX369</dc:creator>
      <dc:date>2025-07-02T07:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/749082#M22540</link>
      <description>&lt;P&gt;A bit less ugly is to use `| sed -n '3,$p' &amp;gt; export.csv `&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2025 09:16:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/749082#M22540</guid>
      <dc:creator>SierraX369</dc:creator>
      <dc:date>2025-07-02T09:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to revert the SPLUNK_HOME ownership?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/751351#M22843</link>
      <description>&lt;P&gt;Still a known issue in Splunk 10.0 :&amp;nbsp;SPL-226019&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 09:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Attempting-to-revert-the-SPLUNK-HOME-ownership/m-p/751351#M22843</guid>
      <dc:creator>yoho</dc:creator>
      <dc:date>2025-08-11T09:54:10Z</dc:date>
    </item>
  </channel>
</rss>

