<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: universal forwarder scripts linux in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69775#M14172</link>
    <description>&lt;P&gt;Bump. I'm having the same issue.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2014 15:53:51 GMT</pubDate>
    <dc:creator>beaunewcomb</dc:creator>
    <dc:date>2014-02-14T15:53:51Z</dc:date>
    <item>
      <title>universal forwarder scripts linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69774#M14171</link>
      <description>&lt;P&gt;I am leveraging the rlog.sh script on a universal forwarder. The forwarder receives it's confuration in the form of a deployment app from a deployment server(windows). When the client pulls the package, the machine recognizes the rlog.sh script as a new file and sets the default permissions (no execute bit due to umask settings). Splunk then throws an error of "permissions denied" when running the script. I can resolve the issue temporarily by adding execute permissions for the owner after the file is pulled to the client, but any time the client pulls the package down again, it resets the permissions. I'm unable to modify our umask values due to security requirements. &lt;BR /&gt;
The rlog.sh script is leveraged in the inputs.conf as follows:&lt;/P&gt;

&lt;P&gt;[script://./bin/rlog.sh]&lt;/P&gt;

&lt;P&gt;sourcetype = auditd&lt;/P&gt;

&lt;P&gt;source = auditd&lt;/P&gt;

&lt;P&gt;interval = 60&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;followTail=1&lt;/P&gt;

&lt;P&gt;Any ideas on how to get splunk to recognize it is an executable without setting permissons for an executable (i.e. rw-r------ instead of (rwxr-----)?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 12:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69774#M14171</guid>
      <dc:creator>jsb22</dc:creator>
      <dc:date>2012-09-25T12:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: universal forwarder scripts linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69775#M14172</link>
      <description>&lt;P&gt;Bump. I'm having the same issue.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2014 15:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69775#M14172</guid>
      <dc:creator>beaunewcomb</dc:creator>
      <dc:date>2014-02-14T15:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: universal forwarder scripts linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69776#M14173</link>
      <description>&lt;P&gt;I´m having to same issue to ! Is the only solution is to install the DS on a linux machine ?&lt;/P&gt;

&lt;P&gt;Thanks for your help&lt;BR /&gt;
Laurent&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 14:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/universal-forwarder-scripts-linux/m-p/69776#M14173</guid>
      <dc:creator>lzaexpert</dc:creator>
      <dc:date>2018-11-30T14:51:16Z</dc:date>
    </item>
  </channel>
</rss>

