<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexing logs in /var/log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23946#M3763</link>
    <description>&lt;P&gt;I eventually did remove the acl permissions and just set new ones w/ chmod.  It seemed the acl permissions were clashing with others on the file.  I added splunk to an admin group and changed the owner of the file to be root:admin.  This finally worked.  However If I could not make all of these changes because of security, is there another way...&lt;/P&gt;</description>
    <pubDate>Mon, 11 Feb 2013 22:05:01 GMT</pubDate>
    <dc:creator>gnovak</dc:creator>
    <dc:date>2013-02-11T22:05:01Z</dc:date>
    <item>
      <title>Indexing logs in /var/log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23945#M3762</link>
      <description>&lt;P&gt;Ok I have been trying to get /var/log/messages and /var/log/cron to be indexed as the "splunk" user for a while and I'm pretty frustrated.&lt;/P&gt;

&lt;P&gt;I read this question here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/60388/recommended-permissions-on-varlog-for-splunk_ta_nix"&gt;http://splunk-base.splunk.com/answers/60388/recommended-permissions-on-varlog-for-splunk_ta_nix&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I followed some of the advice here and set permissions for /var/log directory using ACLs.  I also tried making the splunk user a member of the adm group.  I EVEN got to the point of changing permissions on the file itself with chmod and the file still did not show up as being indexed.  I made sure I restarted splunk each time on the forwarder when I made these changes.&lt;/P&gt;

&lt;P&gt;I'm running Centos 6.2  Has anyone else had this issue?  I could use UDP for port 514 but this way seemed a bit more sense and less config changes.&lt;/P&gt;

&lt;P&gt;The error i found in splunkd.log for this is:&lt;/P&gt;

&lt;P&gt;02-07-2013 13:41:29.441 -0500 WARN  FilesystemChangeWatcher - error getting attributes of path "/var/log/messages": Permission denied&lt;/P&gt;

&lt;P&gt;Obviously these changes aren't making a difference.  Anyone else have this problem?  Someone mentioned to me today "selinux" could be an issue.  I also thought about giving sudo all access for the splunk user.  Anyone else try this?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2013 20:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23945#M3762</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-02-07T20:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing logs in /var/log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23946#M3763</link>
      <description>&lt;P&gt;I eventually did remove the acl permissions and just set new ones w/ chmod.  It seemed the acl permissions were clashing with others on the file.  I added splunk to an admin group and changed the owner of the file to be root:admin.  This finally worked.  However If I could not make all of these changes because of security, is there another way...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2013 22:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23946#M3763</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-02-11T22:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing logs in /var/log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23947#M3764</link>
      <description>&lt;P&gt;I would suggest it's a problem with SELinux.&lt;BR /&gt;
Try to disable it temporarily:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[root@server ~]# getenforce
Enforcing
[root@server ~]# setenforce Permissive
[root@server ~]# getenforce
Permissive
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It's not recommended to disable SELinux unless you know what you're doing, so check out &lt;A href="http://wiki.splunk.com/Community:SplunkOnSELinux"&gt;Splunk on SELinux&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2014 16:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23947#M3764</guid>
      <dc:creator>tfpblanchard</dc:creator>
      <dc:date>2014-06-19T16:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing logs in /var/log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23948#M3765</link>
      <description>&lt;P&gt;In case you get trapped with a file not being monitored even if (1) all permissions seem correct, (2) your deployment script is set to &lt;CODE&gt;Enable App, Restart Splunkd&lt;/CODE&gt; and (3) You see these errors&lt;BR /&gt;
&lt;CODE&gt;09-18-2015 12:28:47.311 +1000 WARN  FilesystemChangeWatcher - error getting attributes of path "/software/app/oracle/admin/webhost1/diagnostics/logs/OHS/ohs1/access_log": Permission denied&lt;/CODE&gt;&lt;BR /&gt;
Then I found this actually did work: &lt;BR /&gt;
- Log on to the forwarder and check that your app with the file monitoring stanza has been deployed all OK&lt;BR /&gt;
- Do a &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; (if you’ve got the same problem it won’t be listed)&lt;BR /&gt;
- Restart of splunk e.g. /opt/splunkforwarder/bin/splunk restart&lt;BR /&gt;
- Do another &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; to see if it has worked&lt;/P&gt;

&lt;P&gt;Unfortunately in this exercise I didn’t do a &lt;CODE&gt;ps | grep splunk&lt;/CODE&gt; on the remote host to check if the splunkforwarder process had been restarted by the utility server’s &lt;CODE&gt;splunk reload deploy-server&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 03:44:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-in-var-log/m-p/23948#M3765</guid>
      <dc:creator>crash1011</dc:creator>
      <dc:date>2015-09-18T03:44:41Z</dc:date>
    </item>
  </channel>
</rss>

