<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunkforwarder stopped forwarding to indexer after ACL change on FS in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481468#M9416</link>
    <description>&lt;P&gt;I assume the directories that were changes may be owned by root permissions. I would suggest you make the following changes &lt;/P&gt;

&lt;P&gt;As root user run the following command: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;chown -R splunk:splunk /opt/splunk/
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 03 Mar 2020 06:04:17 GMT</pubDate>
    <dc:creator>sumanssah</dc:creator>
    <dc:date>2020-03-03T06:04:17Z</dc:date>
    <item>
      <title>splunkforwarder stopped forwarding to indexer after ACL change on FS</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481467#M9415</link>
      <description>&lt;P&gt;I've singe SPF forwarding to 3 indexers in a cluster, after changing the file permissions to rw from rwx the splunk forwarder stopped indexing files from input dirs. have seen logs no clues found. Any suggestions when to look for errors/exceptions. TIA.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 04:51:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481467#M9415</guid>
      <dc:creator>bhupalbobbadi</dc:creator>
      <dc:date>2020-03-03T04:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: splunkforwarder stopped forwarding to indexer after ACL change on FS</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481468#M9416</link>
      <description>&lt;P&gt;I assume the directories that were changes may be owned by root permissions. I would suggest you make the following changes &lt;/P&gt;

&lt;P&gt;As root user run the following command: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;chown -R splunk:splunk /opt/splunk/
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 03 Mar 2020 06:04:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481468#M9416</guid>
      <dc:creator>sumanssah</dc:creator>
      <dc:date>2020-03-03T06:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: splunkforwarder stopped forwarding to indexer after ACL change on FS</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481469#M9417</link>
      <description>&lt;P&gt;Directories have to be executable in order to &lt;EM&gt;do&lt;/EM&gt; anything inside them&lt;/P&gt;

&lt;P&gt;It's the nature of *nix permissioning&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 13:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkforwarder-stopped-forwarding-to-indexer-after-ACL-change/m-p/481469#M9417</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-03T13:46:05Z</dc:date>
    </item>
  </channel>
</rss>

