<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to disable a Deployment Client using a &amp;quot;splunk&amp;quot; user account? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287157#M54840</link>
    <description>&lt;P&gt;Thanks Martin for your response. Thought I already did that in the way you told. However, the issue was, there was no home directory for splunk user so there was home directory. After I created the home directory for splunk and ran the command the issue got resolved.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2016 01:50:20 GMT</pubDate>
    <dc:creator>splunk_kk</dc:creator>
    <dc:date>2016-04-12T01:50:20Z</dc:date>
    <item>
      <title>Why am I unable to disable a Deployment Client using a "splunk" user account?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287155#M54838</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;

&lt;P&gt;I have installed a Splunk Universal Forwarder in my environment and set the deployment server. I also have an account named "splunk" which owns /opt/splunkforwarder.&lt;/P&gt;

&lt;P&gt;However, if I sudo to Splunk and then disable the deployment client, I'm not able to do so. I get a permission deny error. However, If I sudo to root, I'm able to disable the deployment client.&lt;/P&gt;

&lt;P&gt;Any help why it is so?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 07:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287155#M54838</guid>
      <dc:creator>splunk_kk</dc:creator>
      <dc:date>2016-04-11T07:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to disable a Deployment Client using a "splunk" user account?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287156#M54839</link>
      <description>&lt;P&gt;I'm guessing your forwarder runs as root, or some other user. Check with &lt;CODE&gt;ps -Af | grep splunkd&lt;/CODE&gt; or similar to confirm.&lt;/P&gt;

&lt;P&gt;Assuming you don't need the forwarder to run as root (if you do, work to remove that need), you should stop the forwarder, chown all files to splunk, run splunk enable boot-start -user splunk, and start splunk from the user splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 21:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287156#M54839</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-04-11T21:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to disable a Deployment Client using a "splunk" user account?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287157#M54840</link>
      <description>&lt;P&gt;Thanks Martin for your response. Thought I already did that in the way you told. However, the issue was, there was no home directory for splunk user so there was home directory. After I created the home directory for splunk and ran the command the issue got resolved.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 01:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-disable-a-Deployment-Client-using-a-quot/m-p/287157#M54840</guid>
      <dc:creator>splunk_kk</dc:creator>
      <dc:date>2016-04-12T01:50:20Z</dc:date>
    </item>
  </channel>
</rss>

