<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the path of Splunk data in any Linux server? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366509#M13551</link>
    <description>&lt;P&gt;Yes, &lt;CODE&gt;SELinux&lt;/CODE&gt; is VERY bad mojo so check that and kill it.  Also, what does &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; show?&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2017 20:48:06 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-07-07T20:48:06Z</dc:date>
    <item>
      <title>What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366499#M13541</link>
      <description>&lt;P&gt;I spoke with Linux admin to allow permissions to Splunk app, he asked me what is the path of Splunk logs so that he can allow permissions.. kindly guide !! We can't give root permissions to Splunk forwarder as per policy.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 16:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366499#M13541</guid>
      <dc:creator>splunkiri</dc:creator>
      <dc:date>2017-06-29T16:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366500#M13542</link>
      <description>&lt;P&gt;You're doing well by not running Splunk as root.&lt;BR /&gt;
Splunk's logs are in $SPLUNK_HOME/var/log/splunk.  Permissions should already be granted to the owner of Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 17:31:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366500#M13542</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-06-29T17:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366501#M13543</link>
      <description>&lt;P&gt;Is this a splunk forwarder or a splunk indexer?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 19:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366501#M13543</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-29T19:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366502#M13544</link>
      <description>&lt;P&gt;Hi, Thanks for the answer. Which permissions should I grant to Splunk directories available in the path $SPLUNK_HOME/var/log/splunk. Kindly reply asap.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 14:37:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366502#M13544</guid>
      <dc:creator>splunkiri</dc:creator>
      <dc:date>2017-07-05T14:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366503#M13545</link>
      <description>&lt;P&gt;Hi, I want to give persmissions to Splunk Forwarder not Splunk indexer. Kindly guide. What permissions do I need to provide ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 19:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366503#M13545</guid>
      <dc:creator>splunkiri</dc:creator>
      <dc:date>2017-07-05T19:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366504#M13546</link>
      <description>&lt;P&gt;For forwarders you need read-only for the stuff that you are forwarding and you need write permission for everything under &lt;CODE&gt;$SPLUNK_HOME&lt;/CODE&gt; which by default on *nix is &lt;CODE&gt;/opt/splunk/&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 22:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366504#M13546</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-05T22:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366505#M13547</link>
      <description>&lt;P&gt;I already provide the same permissions, kindly have a look,&lt;BR /&gt;
Still forwarder is not sending the data.. kindly guide..&lt;/P&gt;

&lt;P&gt;drwx------ 2 splunk splunk 4096 Oct 16  2016 /opt/splunkforwarder/var/log/introspection&lt;BR /&gt;
drwx------ 2 splunk splunk 4096 Jul  5 22:02 /opt/splunkforwarder/var/log/splunk &lt;/P&gt;

&lt;P&gt;lnx0591:root# ls -ltr&lt;BR /&gt;
total 261064&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 splunkd_ui_access.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 searchhistory.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 scheduler.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 remote_searches.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 mongod.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 license_usage.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 license_audit.log&lt;BR /&gt;
-rw------- 1 splunk splunk       64 Oct 16  2016 first_install.log&lt;BR /&gt;
-rw------- 1 splunk splunk     5817 Jan  9 15:54 splunkd_access.log&lt;BR /&gt;
-rw------- 1 splunk splunk 25000073 Jan 22 19:58 splunkd.log.5&lt;BR /&gt;
-rw------- 1 splunk splunk 25000123 Mar 12 09:45 splunkd.log.4&lt;BR /&gt;
-rw------- 1 splunk splunk 25000040 Apr 29 00:53 splunkd.log.3&lt;BR /&gt;
-rw------- 1 splunk splunk      299 Jun 14 14:45 splunkd_stdout.log&lt;BR /&gt;
-rw------- 1 splunk splunk 25000178 Jun 15 10:19 splunkd.log.2&lt;BR /&gt;
-rw------- 1 splunk splunk 25000171 Jun 26 19:25 metrics.log.5&lt;BR /&gt;
-rw------- 1 splunk splunk     5825 Jun 28 10:41 splunkd-utility.log&lt;BR /&gt;
-rw------- 1 splunk splunk      296 Jun 28 10:41 btool.log&lt;BR /&gt;
-rw------- 1 splunk splunk      482 Jun 28 10:41 splunkd_stderr.log&lt;BR /&gt;
-rw------- 1 splunk splunk     1336 Jun 28 10:46 conf.log&lt;BR /&gt;
-rw------- 1 splunk splunk 25000124 Jun 29 02:02 metrics.log.4&lt;BR /&gt;
-rw------- 1 splunk splunk 25000107 Jun 29 04:23 splunkd.log.1&lt;BR /&gt;
-rw------- 1 splunk splunk   160573 Jul  1 03:38 audit.log&lt;BR /&gt;
-rw------- 1 splunk splunk 25000011 Jul  1 08:44 metrics.log.3&lt;BR /&gt;
-rw------- 1 splunk splunk 25000141 Jul  3 15:25 metrics.log.2&lt;BR /&gt;
-rw------- 1 splunk splunk 25000088 Jul  5 22:02 metrics.log.1&lt;BR /&gt;
-rw------- 1 splunk splunk  3887362 Jul  6 06:32 metrics.log&lt;BR /&gt;
-rw------- 1 splunk splunk 12901867 Jul  6 06:32 splunkd.log&lt;BR /&gt;
lnx0591:root# &lt;/P&gt;

&lt;P&gt;lnx0591:root# ls -lR  /opt/splunkforwarder/var/log/&lt;BR /&gt;
/opt/splunkforwarder/var/log/:&lt;BR /&gt;
total 8&lt;BR /&gt;
drwx------ 2 splunk splunk 4096 Oct 16  2016 introspection&lt;BR /&gt;
drwx------ 2 splunk splunk 4096 Jul  5 22:02 splunk&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/var/log/introspection:&lt;BR /&gt;
total 5028&lt;BR /&gt;
-rw------- 1 splunk splunk 5133404 Jul  6 06:41 disk_objects.log&lt;BR /&gt;
-rw------- 1 splunk splunk       0 Oct 16  2016 kvstore.log&lt;BR /&gt;
-rw------- 1 splunk splunk       0 Oct 16  2016 resource_usage.log&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/var/log/splunk:&lt;BR /&gt;
total 261140&lt;BR /&gt;
-rw------- 1 splunk splunk   160573 Jul  1 03:38 audit.log&lt;BR /&gt;
-rw------- 1 splunk splunk      296 Jun 28 10:41 btool.log&lt;BR /&gt;
-rw------- 1 splunk splunk     1336 Jun 28 10:46 conf.log&lt;BR /&gt;
-rw------- 1 splunk splunk       64 Oct 16  2016 first_install.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 license_audit.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 license_usage.log&lt;BR /&gt;
-rw------- 1 splunk splunk  3953315 Jul  6 06:41 metrics.log&lt;BR /&gt;
-rw------- 1 splunk splunk 25000088 Jul  5 22:02 metrics.log.1&lt;BR /&gt;
-rw------- 1 splunk splunk 25000141 Jul  3 15:25 metrics.log.2&lt;BR /&gt;
-rw------- 1 splunk splunk 25000011 Jul  1 08:44 metrics.log.3&lt;BR /&gt;
-rw------- 1 splunk splunk 25000124 Jun 29 02:02 metrics.log.4&lt;BR /&gt;
-rw------- 1 splunk splunk 25000171 Jun 26 19:25 metrics.log.5&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 mongod.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 remote_searches.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 scheduler.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 searchhistory.log&lt;BR /&gt;
-rw------- 1 splunk splunk     5817 Jan  9 15:54 splunkd_access.log&lt;BR /&gt;
-rw------- 1 splunk splunk 12912781 Jul  6 06:40 splunkd.log&lt;BR /&gt;
-rw------- 1 splunk splunk 25000107 Jun 29 04:23 splunkd.log.1&lt;BR /&gt;
-rw------- 1 splunk splunk 25000178 Jun 15 10:19 splunkd.log.2&lt;BR /&gt;
-rw------- 1 splunk splunk 25000040 Apr 29 00:53 splunkd.log.3&lt;BR /&gt;
-rw------- 1 splunk splunk 25000123 Mar 12 09:45 splunkd.log.4&lt;BR /&gt;
-rw------- 1 splunk splunk 25000073 Jan 22 19:58 splunkd.log.5&lt;BR /&gt;
-rw------- 1 splunk splunk      482 Jun 28 10:41 splunkd_stderr.log&lt;BR /&gt;
-rw------- 1 splunk splunk      299 Jun 14 14:45 splunkd_stdout.log&lt;BR /&gt;
-rw------- 1 splunk splunk        0 Oct 16  2016 splunkd_ui_access.log&lt;BR /&gt;
-rw------- 1 splunk splunk     5825 Jun 28 10:41 splunkd-utility.log&lt;BR /&gt;
lnx0591:root# &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366505#M13547</guid>
      <dc:creator>splunkiri</dc:creator>
      <dc:date>2020-09-29T14:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366506#M13548</link>
      <description>&lt;P&gt;Have you verified the Forwarder is running as user 'splunk'?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 21:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366506#M13548</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-06T21:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366507#M13549</link>
      <description>&lt;P&gt;Yes, Forwarder is running as a Splunk. I also gave the -rw permissions. but it is sending data only through the sourcetype- Syslog and not from any other. Kindly guide, do we need to give permissions differently to the Splunk user and inside dir.s and files ? and if so, what types of permissions do I need to provide ?  &lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 14:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366507#M13549</guid>
      <dc:creator>splunkiri</dc:creator>
      <dc:date>2017-07-07T14:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366508#M13550</link>
      <description>&lt;P&gt;I'm at a loss.  Are you running SELinux?&lt;BR /&gt;
Any ideas, @woodcock?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 20:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366508#M13550</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-07-07T20:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366509#M13551</link>
      <description>&lt;P&gt;Yes, &lt;CODE&gt;SELinux&lt;/CODE&gt; is VERY bad mojo so check that and kill it.  Also, what does &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; show?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 20:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/366509#M13551</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-07T20:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: What is the path of Splunk data in any Linux server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/564415#M24799</link>
      <description>&lt;P&gt;IMHO: I think there is some confusion here. The OP wants to ingest logs on the host via the SUF.&lt;/P&gt;&lt;P&gt;So permissions for `splunk` need to be granted on, for example `/var/log/messages` either via group or `setfacl`.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 19:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-the-path-of-Splunk-data-in-any-Linux-server/m-p/564415#M24799</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2021-08-23T19:26:37Z</dc:date>
    </item>
  </channel>
</rss>

