<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk group in linux in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674952#M112966</link>
    <description>&lt;P&gt;I have updated the universal forwarder with RPM and deb packages and following commands:&lt;/P&gt;&lt;P&gt;rpm -Uvh and dpkg -i&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jan 2024 11:54:03 GMT</pubDate>
    <dc:creator>maede_yavari</dc:creator>
    <dc:date>2024-01-21T11:54:03Z</dc:date>
    <item>
      <title>splunk group in linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674949#M112964</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I noticed that in versions upper 9.1, the user and group were changed to "splunkfwd"&lt;/P&gt;&lt;P&gt;I have updated the universal forwarder to the newer version (9.1), but the user and group did not change to "splunkfwd." Subsequently, we encountered several problems related to permissions, such as the Universal Forwarder lacking permission to read auditd logs. Therefore, it is necessary to modify the "log_group" parameter in the auditd.conf file.&lt;/P&gt;&lt;P&gt;Should I manually change it, or is there an alternative solution to resolve all permission problems?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 09:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674949#M112964</guid>
      <dc:creator>maede_yavari</dc:creator>
      <dc:date>2024-01-21T09:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: splunk group in linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674950#M112965</link>
      <description>&lt;P&gt;How did you install and upgrade your forwarder? RPM? deb? tgz?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 11:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674950#M112965</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-21T11:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: splunk group in linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674952#M112966</link>
      <description>&lt;P&gt;I have updated the universal forwarder with RPM and deb packages and following commands:&lt;/P&gt;&lt;P&gt;rpm -Uvh and dpkg -i&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 11:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674952#M112966</guid>
      <dc:creator>maede_yavari</dc:creator>
      <dc:date>2024-01-21T11:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk group in linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674955#M112969</link>
      <description>&lt;P&gt;Wait a second. You did both on the same host? rpm and deb?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2024 14:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674955#M112969</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-21T14:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: splunk group in linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674989#M112975</link>
      <description>&lt;P&gt;I have updated the universal forwarder with RPM and deb packages and following commands:&lt;/P&gt;&lt;P&gt;rpm -Uvh and dpkg -i&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 05:19:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-group-in-linux/m-p/674989#M112975</guid>
      <dc:creator>maede_yavari</dc:creator>
      <dc:date>2024-01-22T05:19:52Z</dc:date>
    </item>
  </channel>
</rss>

