<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440067#M76754</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This is due to systemd changes introduced by Splunk in 7.2.2, have a look at answers post &lt;A href="https://answers.splunk.com/answers/738877/splunk-systemd-unit-file-in-versions-722-and-newer.html"&gt;https://answers.splunk.com/answers/738877/splunk-systemd-unit-file-in-versions-722-and-newer.html&lt;/A&gt; which explains this behavior and solution. &lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2019 09:13:34 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2019-06-24T09:13:34Z</dc:date>
    <item>
      <title>After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440065#M76752</link>
      <description>&lt;P&gt;after upgrading forwarder to 7.2.6 it's not getting controlled by Splunk user(specifically aligned to Splunk only (non-root user))  while restarting service.&lt;/P&gt;

&lt;P&gt;We upgrade Splunk UF to 7.2.6 from 6.x.x , everything is working as expected but while stop\start splunk service it's asking for authentication (mentioned below). And this message coming only once we enable boot start for Splunk user so that It can auto start after reboot. If we disable boot start then I am not getting these messages.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[user@servername ~]$ /usr/splunk/splunkforwarder/bin/splunk restart
Stopping splunkd...
Shutting down.  Please wait, as this may take a few minutes.
==== AUTHENTICATING FOR org.freedesktop.systemd1.manage-units ===
Authentication is required to manage system services or units.
Multiple identities can be used for authentication:
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And you will get multiple user identities here after this  above line, these are the user who's ID is synced with root user. And if I ask them to do they are able to restart Splunk but they have to choose their username and password , so to add splunk user here in identities list what we need to do. Is there a way to get rid of this.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Splunk UF version - 7.2.6
OS version - Red Hat Enterprise Linux Server release 7.6 (Maipo)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Do we need to tweak splunk configuration or make any entries in sudoer files on OS side.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 07:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440065#M76752</guid>
      <dc:creator>ashikuma</dc:creator>
      <dc:date>2019-06-24T07:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440066#M76753</link>
      <description>&lt;P&gt;Hi @ashikuma,&lt;/P&gt;

&lt;P&gt;Did you follow the steps mentioned here :&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/RunSplunkassystemdservice#Configure_systemd_using_enable_boot-start"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/RunSplunkassystemdservice#Configure_systemd_using_enable_boot-start&lt;/A&gt; &lt;BR /&gt;
How did you set this up exactly ?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 08:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440066#M76753</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-24T08:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440067#M76754</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This is due to systemd changes introduced by Splunk in 7.2.2, have a look at answers post &lt;A href="https://answers.splunk.com/answers/738877/splunk-systemd-unit-file-in-versions-722-and-newer.html"&gt;https://answers.splunk.com/answers/738877/splunk-systemd-unit-file-in-versions-722-and-newer.html&lt;/A&gt; which explains this behavior and solution. &lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440067#M76754</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-06-24T09:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440068#M76755</link>
      <description>&lt;P&gt;This is due to Splunk using systemd to manage the Splunk process by default in certain 7.2.x versions. If you want to get rid of this, you can enable boot start with the old method by adding &lt;CODE&gt;-systemd-managed 0&lt;/CODE&gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/RunSplunkassystemdservice#Additional_options_for_enable_boot-start"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/RunSplunkassystemdservice#Additional_options_for_enable_boot-start&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440068#M76755</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-06-24T09:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440069#M76756</link>
      <description>&lt;P&gt;Update: Since 7.3 default is &lt;CODE&gt;-systemd-managed 0&lt;/CODE&gt; (Splunk reverted default configuration which they introduced in 7.2.2)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:17:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440069#M76756</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-06-24T09:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440070#M76757</link>
      <description>&lt;P&gt;we enabled it using command :  /usr/splunk/splunkforwarder/bin/splunk enable boot-start -user &lt;BR /&gt;
and it's making entries under /etc/init.d/splunk in linux boxes, but when we upgraded it to 7.2.6 we lost control on stop\start service , so as per above document do we need to use systemd to control splunk.&lt;BR /&gt;
My questions is same thing working in splunk UF version lowes version 6.x.x but not on 7.2.6.&lt;/P&gt;

&lt;P&gt;I would say just try same to install in your test env. once for same scenario. &lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440070#M76757</guid>
      <dc:creator>ashikuma</dc:creator>
      <dc:date>2019-06-24T09:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440071#M76758</link>
      <description>&lt;P&gt;Oh, cool, didn't know that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Edited my answer to clarify systemd is only the default in certain 7.2.x versions.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440071#M76758</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-06-24T09:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440072#M76759</link>
      <description>&lt;P&gt;sudoers will not resolve this problem, refer to FrankVI's comments around the systemd usage in Splunk 7.2&lt;BR /&gt;
If you choose to stay with systemd in the particular Splunk 7.2 version or above refer to:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/738877/splunk-systemd-unit-file-in-versions-722-and-newer.html"&gt;https://answers.splunk.com/answers/738877/splunk-systemd-unit-file-in-versions-722-and-newer.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;That will provide a solution to remove the password prompt, if not feel free to use init.d if that is preferred!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 22:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440072#M76759</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2019-06-24T22:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: After upgrading forwarder to 7.2.6 why is it not getting controlled by splunk user while restarting service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440073#M76760</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Summary of the issue:&lt;/STRONG&gt;&lt;BR /&gt;
Splunk 6.0.0 - Splunk 7.2.1 defaults to using &lt;STRONG&gt;init.d&lt;/STRONG&gt; when enabling boot start&lt;BR /&gt;
Splunk 7.2.2 - Splunk 7.2.9 defaults to using &lt;STRONG&gt;systemd&lt;/STRONG&gt; when enabling boot start&lt;BR /&gt;
Splunk 7.3.0 - Splunk 8.x defaults to using &lt;STRONG&gt;init.d&lt;/STRONG&gt; when enabling boot start&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;systemd&lt;/STRONG&gt; defaults to prompting for root credentials upon stop/start/restart of Splunk&lt;/P&gt;

&lt;P&gt;Here is a simple fix if you have encountered this issue and prefer to use the traditional &lt;STRONG&gt;init.d&lt;/STRONG&gt; scripts vs &lt;STRONG&gt;systemd&lt;/STRONG&gt;. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Splunk Enterprise/Heavy Forwarder example&lt;/STRONG&gt; (note: replace the splunk user below with the account you run splunk as):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo /opt/splunk/bin/splunk disable boot-start
sudo /opt/splunk/bin/splunk enable boot-start -user splunk -systemd-managed 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Splunk Universal Forwarder example&lt;/STRONG&gt; (note: replace the splunk user below with the account you run splunk as):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo /opt/splunkforwarder/bin/splunk disable boot-start
sudo /opt/splunkforwarder/bin/splunk enable boot-start -user splunk -systemd-managed 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 31 Dec 2019 18:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-upgrading-forwarder-to-7-2-6-why-is-it-not-getting/m-p/440073#M76760</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2019-12-31T18:43:23Z</dc:date>
    </item>
  </channel>
</rss>

