<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UF monitoring logs that is not accessible to is underlying user in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564068#M100466</link>
    <description>&lt;P&gt;Got it&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;, I just cant find an article that would support this observation of mine.&lt;/P&gt;&lt;P&gt;Thank you! :&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Aug 2021 09:49:32 GMT</pubDate>
    <dc:creator>MrYanYan</dc:creator>
    <dc:date>2021-08-20T09:49:32Z</dc:date>
    <item>
      <title>Splunk UF monitoring logs that is not accessible to is underlying user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564063#M100463</link>
      <description>&lt;P&gt;Hi Fellas!&lt;/P&gt;&lt;P&gt;I just wanted to ask if it would be possible for a Splunk UF to monitor logs that is not accessible to its underlying user.&lt;/P&gt;&lt;P&gt;For example, I am running my Splunk UF instance under the &lt;EM&gt;splunk user&lt;/EM&gt; and I am try to capture data from files under the directory &lt;EM&gt;/var/logs/appservicename/*.log&lt;/EM&gt; which is owned by &lt;EM&gt;root user&lt;/EM&gt;. Given the I have the correct configuration at inputs.conf and outputs.conf, will the data be transmitted to my indexer instance?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 09:40:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564063#M100463</guid>
      <dc:creator>MrYanYan</dc:creator>
      <dc:date>2021-08-20T09:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF monitoring logs that is not accessible to is underlying user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564064#M100464</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237630"&gt;@MrYanYan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if the user thet you user to run Splunk hasn't the right to read the files in a folder, you cannot do it obviously!&lt;/P&gt;&lt;P&gt;The only ways are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;insert the splunk user in the root group,&lt;/LI&gt;&lt;LI&gt;temporary create a copy of those files in another folder accessible from splunk user and then delete them after few minutes.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 09:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564064#M100464</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-08-20T09:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF monitoring logs that is not accessible to is underlying user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564067#M100465</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237630"&gt;@MrYanYan&lt;/a&gt;&amp;nbsp; Splunk user must be able to read the file owned by root user to monitor the file.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 09:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564067#M100465</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-20T09:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF monitoring logs that is not accessible to is underlying user</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564068#M100466</link>
      <description>&lt;P&gt;Got it&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;, I just cant find an article that would support this observation of mine.&lt;/P&gt;&lt;P&gt;Thank you! :&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 09:49:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-UF-monitoring-logs-that-is-not-accessible-to-is/m-p/564068#M100466</guid>
      <dc:creator>MrYanYan</dc:creator>
      <dc:date>2021-08-20T09:49:32Z</dc:date>
    </item>
  </channel>
</rss>

