<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On which user my Splunk is running? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363043#M93873</link>
    <description>&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I created the user and group called splunk and then ran Splunk for the first time with splunk user // &lt;BR /&gt;
not sure of this step. can you please explain.. this is on Splunk indexer or Splunk forwarder or.. &lt;/P&gt;

&lt;P&gt;root 1658 1473 0 22:33 pts/0 00:00:00 su - splunk&lt;BR /&gt;
i am not sure of why you have to switch user to splunk user. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;when you run &lt;CODE&gt;ps -ef | grep splunk&lt;/CODE&gt;,   (please note on your command, you used ps -af".. instead use "ps -ef") &lt;BR /&gt;
what output you get ?!?!&lt;/P&gt;</description>
    <pubDate>Sun, 01 Oct 2017 22:42:02 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-10-01T22:42:02Z</dc:date>
    <item>
      <title>On which user my Splunk is running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363041#M93871</link>
      <description>&lt;P&gt;Not that familiar with *NIX hence the question. &lt;/P&gt;

&lt;P&gt;I created the user and group called splunk and then ran Splunk for the first time with splunk user. &lt;/P&gt;

&lt;P&gt;Now I want to ensure my Splunk is  running as splunk user and not as root. &lt;BR /&gt;
Can someone help me below command and the output?&lt;/P&gt;

&lt;P&gt;-bash-4.2$ ps -af|grep splunk&lt;BR /&gt;
root      1658  1473  0 22:33 pts/0    00:00:00 su - splunk&lt;BR /&gt;
splunk    1659  1658  0 22:33 pts/0    00:00:00 -bash&lt;BR /&gt;
splunk    2121  1659  0 22:36 pts/0    00:00:00 ps -af&lt;BR /&gt;
splunk    2122  1659  0 22:36 pts/0    00:00:00 grep --color=auto splunk&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2017 18:50:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363041#M93871</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2017-10-01T18:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: On which user my Splunk is running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363042#M93872</link>
      <description>&lt;P&gt;ah okay so I then ran splunk status and it gave me the PID. &lt;BR /&gt;
I can see the PID is running as splunk user. &lt;/P&gt;

&lt;P&gt;I think I got what I was looking for.&lt;/P&gt;

&lt;P&gt;Cannot delete the question as its irrelevant now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2017 19:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363042#M93872</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2017-10-01T19:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: On which user my Splunk is running?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363043#M93873</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I created the user and group called splunk and then ran Splunk for the first time with splunk user // &lt;BR /&gt;
not sure of this step. can you please explain.. this is on Splunk indexer or Splunk forwarder or.. &lt;/P&gt;

&lt;P&gt;root 1658 1473 0 22:33 pts/0 00:00:00 su - splunk&lt;BR /&gt;
i am not sure of why you have to switch user to splunk user. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;when you run &lt;CODE&gt;ps -ef | grep splunk&lt;/CODE&gt;,   (please note on your command, you used ps -af".. instead use "ps -ef") &lt;BR /&gt;
what output you get ?!?!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2017 22:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/On-which-user-my-Splunk-is-running/m-p/363043#M93873</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-10-01T22:42:02Z</dc:date>
    </item>
  </channel>
</rss>

