<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal forwarder for Linux had mixture of permissions for root and splunk. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-for-Linux-had-mixture-of-permissions-for/m-p/531773#M89447</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working with a Linux system and a universal forwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Operating System: Debian GNU/Linux 10 (buster)
            Kernel: Linux 4.19.0-12-amd64
      Architecture: x86-64&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I checked &lt;STRONG&gt;opt/splunkforwarder/etc/system/local&amp;nbsp;&lt;/STRONG&gt; and ran &lt;STRONG&gt;ls -l&amp;nbsp;&lt;/STRONG&gt;I noticed that root root had permission in there as well as splunk splunk. Should splunk splunk own everything in the universal forwarder directory?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;-rw-r--r-- 1 root   root   283 Apr 30  2020 inputs.conf
-rw------- 1 root   root    45 Apr 21  2020 migration.conf
-rw-r--r-- 1 root   root   222 Apr 23  2020 outputs.conf
-r--r--r-- 1 splunk splunk 265 Mar 30  2020 README
-rw------- 1 splunk splunk 431 Sep 23  2019 server.conf
-rw-r--r-- 1 splunk splunk  65 Jun  3 13:38 user-seed.conf
-rw-r--r-- 1 root   root    40 Sep 23  2019 web.conf&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Dec 2020 21:40:05 GMT</pubDate>
    <dc:creator>splunktrainingu</dc:creator>
    <dc:date>2020-12-02T21:40:05Z</dc:date>
    <item>
      <title>Universal forwarder for Linux had mixture of permissions for root and splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-for-Linux-had-mixture-of-permissions-for/m-p/531773#M89447</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working with a Linux system and a universal forwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Operating System: Debian GNU/Linux 10 (buster)
            Kernel: Linux 4.19.0-12-amd64
      Architecture: x86-64&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I checked &lt;STRONG&gt;opt/splunkforwarder/etc/system/local&amp;nbsp;&lt;/STRONG&gt; and ran &lt;STRONG&gt;ls -l&amp;nbsp;&lt;/STRONG&gt;I noticed that root root had permission in there as well as splunk splunk. Should splunk splunk own everything in the universal forwarder directory?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;-rw-r--r-- 1 root   root   283 Apr 30  2020 inputs.conf
-rw------- 1 root   root    45 Apr 21  2020 migration.conf
-rw-r--r-- 1 root   root   222 Apr 23  2020 outputs.conf
-r--r--r-- 1 splunk splunk 265 Mar 30  2020 README
-rw------- 1 splunk splunk 431 Sep 23  2019 server.conf
-rw-r--r-- 1 splunk splunk  65 Jun  3 13:38 user-seed.conf
-rw-r--r-- 1 root   root    40 Sep 23  2019 web.conf&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 21:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-for-Linux-had-mixture-of-permissions-for/m-p/531773#M89447</guid>
      <dc:creator>splunktrainingu</dc:creator>
      <dc:date>2020-12-02T21:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder for Linux had mixture of permissions for root and splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-for-Linux-had-mixture-of-permissions-for/m-p/533199#M89570</link>
      <description>&lt;P&gt;Installation might have been done in root &amp;amp; service is running under splunk user which could have created the splunk file. Changing it to splunk user will not have any impact if service is running under splunk.&lt;/P&gt;&lt;P&gt;chown splunk:splunk /opt/splunkforwarder&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 17:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-for-Linux-had-mixture-of-permissions-for/m-p/533199#M89570</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2020-12-15T17:12:11Z</dc:date>
    </item>
  </channel>
</rss>

