<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able access logs in splunk docker image . in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/497144#M84761</link>
    <description>&lt;P&gt;You will need to update your makefile if building your own image, and set the Splunk user.&lt;BR /&gt;
If using a Splunk supported image, set the Splunk user as a parameter in your run command (-e "SPLUNK_USER=splunk"), e.g.&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2020 00:30:13 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2020-05-20T00:30:13Z</dc:date>
    <item>
      <title>Why am I Not able access logs in splunk docker image?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/497143#M84760</link>
      <description>&lt;P&gt;Whenever I am trying to login to splunk through docker image , the default user is ansible beacsue of that I am not able to access logs and var directory in splunk . &lt;BR /&gt;And not permitted to create a new directory too&lt;/P&gt;
&lt;P&gt;kindly suggest.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 12:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/497143#M84760</guid>
      <dc:creator>icanwin</dc:creator>
      <dc:date>2022-07-13T12:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Not able access logs in splunk docker image .</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/497144#M84761</link>
      <description>&lt;P&gt;You will need to update your makefile if building your own image, and set the Splunk user.&lt;BR /&gt;
If using a Splunk supported image, set the Splunk user as a parameter in your run command (-e "SPLUNK_USER=splunk"), e.g.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 00:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/497144#M84761</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-05-20T00:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Not able access logs in splunk docker image .</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/605383#M105238</link>
      <description>&lt;P&gt;I added&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;SPLUNK_USER=splunk to the docker-compose yml file and restarted the container.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Here is the environment.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ansible@28f74f55c15a splunk]$ env&lt;/P&gt;&lt;P&gt;LANG=C.utf8&lt;/P&gt;&lt;P&gt;HOSTNAME=28f74f55c15a&lt;/P&gt;&lt;P&gt;ANSIBLE_USER=ansible&lt;/P&gt;&lt;P&gt;SPLUNK_HEC_TOKEN=test1234&lt;/P&gt;&lt;P&gt;container=oci&lt;/P&gt;&lt;P&gt;SPLUNK_HOME=/opt/splunk&lt;/P&gt;&lt;P&gt;SCLOUD_URL=&lt;A href="https://github.com/splunk/splunk-cloud-sdk-go/releases/download/v1.11.1/scloud_v7.1.0_linux_amd64.tar.gz" target="_blank" rel="noopener"&gt;https://github.com/splunk/splunk-cloud-sdk-go/releases/download/v1.11.1/scloud_v7.1.0_linux_amd64.tar.gz&lt;/A&gt;&lt;/P&gt;&lt;P&gt;CONTAINER_ARTIFACT_DIR=/opt/container_artifact&lt;/P&gt;&lt;P&gt;PWD=/opt/splunk&lt;/P&gt;&lt;P&gt;HOME=/home/ansible&lt;/P&gt;&lt;P&gt;SPLUNK_DEFAULTS_URL=&lt;/P&gt;&lt;P&gt;SPLUNK_GROUP=splunk&lt;/P&gt;&lt;P&gt;SPLUNK_ANSIBLE_HOME=/opt/ansible&lt;/P&gt;&lt;P&gt;TERM=xterm&lt;/P&gt;&lt;P&gt;SPLUNK_ROLE=splunk_standalone&lt;/P&gt;&lt;P&gt;SPLUNK_PASSWORD=A#123#aaa&lt;/P&gt;&lt;P&gt;PYTHON_GPG_KEY_ID=####&lt;/P&gt;&lt;P&gt;TMPSPLUNKDIR=/opt/splunk/tmp&lt;/P&gt;&lt;P&gt;PYTHON_VERSION=3.7.10&lt;/P&gt;&lt;P&gt;ANSIBLE_GROUP=ansible&lt;/P&gt;&lt;P&gt;SPLUNK_START_ARGS=--accept-license&lt;/P&gt;&lt;P&gt;TMPETCDIR=/opt/splunk/tmp/etc&lt;/P&gt;&lt;P&gt;SHLVL=1&lt;/P&gt;&lt;P&gt;SPLUNK_USER=splunk&lt;/P&gt;&lt;P&gt;PATH=/home/ansible/.local/bin:/home/ansible/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin&lt;/P&gt;&lt;P&gt;_=/usr/bin/env&lt;/P&gt;&lt;P&gt;[ansible@28f74f55c15a splunk]$ whoami&lt;/P&gt;&lt;P&gt;ansible&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;There is no change in from ansible to splunk. Due to this unable to browse some /opt/splunk files as facing persmission issue. Not sure what other changed needed to environment file. Please check&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 05:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-Not-able-access-logs-in-splunk-docker-image/m-p/605383#M105238</guid>
      <dc:creator>rxgampa</dc:creator>
      <dc:date>2022-07-13T05:53:24Z</dc:date>
    </item>
  </channel>
</rss>

