<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forwarder cannot forward events in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574267#M10850</link>
    <description>Sounds like user splunk hasn’t login shell / rights. Can you try sudo -u splunk bash if that is working?</description>
    <pubDate>Tue, 09 Nov 2021 18:05:00 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-11-09T18:05:00Z</dc:date>
    <item>
      <title>Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573891#M10836</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a HF running in Linux machine. I have root access to that machine using &lt;STRONG&gt;sudo bash&amp;nbsp;&lt;/STRONG&gt; as&lt;STRONG&gt; sudo - splunk or su - splunk &lt;/STRONG&gt;is&amp;nbsp; not allowing me to get root access. But, when I copy files to the folders&amp;nbsp; where&lt;STRONG&gt; monitor command&lt;/STRONG&gt; pointing to pickup the files,&amp;nbsp; it is not forwarding events to the SPLUNK indexer since I cannot see those events within SPLUNK. However, when I type &lt;STRONG&gt;chown -R splunk: splunk/opt/splunk and then restart &lt;/STRONG&gt;SPLUNK, it's working as expected, that means I can see those events within SPLUNK. So, every time when I copy&amp;nbsp; files within HF folders, I need to use &lt;STRONG&gt;chown&lt;/STRONG&gt; command and &lt;STRONG&gt;restart&lt;/STRONG&gt; SPLUNK to make them available within SPLUNK. Is there anyway this can be resolved that I don't need to type &lt;STRONG&gt;chown&lt;/STRONG&gt; command and &lt;STRONG&gt;restart&lt;/STRONG&gt; SPLUNK to forward events.&amp;nbsp; Thank you so much.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Nov 2021 04:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573891#M10836</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-06T04:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573893#M10837</link>
      <description>&lt;P&gt;Short answer - no, you can't help the fact that files have wrong ownership/permissions. That's what the whole permission system is for.&lt;/P&gt;&lt;P&gt;Long answer - in general, you shouldn't copy files into /opt/splunk. The proper approach would be to write the log files normally to - for example - /var/log/somewhere or /opt/your_service/var/log and add a monitor input to splunk reading directly from there. Then you should make sure that splunk user has access to those files (possibly by means of proper umasks, group membership and acls).&lt;/P&gt;</description>
      <pubDate>Sat, 06 Nov 2021 08:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573893#M10837</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-06T08:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573909#M10838</link>
      <description>&lt;P&gt;Hello Picklerick,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me explain a little more how I copy the source files. I create app and use&amp;nbsp; GUI feature &lt;STRONG&gt;"Install app from file"&amp;nbsp;&lt;/STRONG&gt; to pull the source files into SPLUNK HF &lt;STRONG&gt;opt/splunk/etc/apps/TA-my_sourcefile&amp;nbsp;&lt;/STRONG&gt; folder and then copy those source files from that folder to &lt;STRONG&gt;/opt/splunk/var/log/sourcefiles&amp;nbsp; &lt;/STRONG&gt;and&amp;nbsp;add a monitor input to SPLUNK reading directly from there.&amp;nbsp; Only problem now how would I make sure to have access as SPLUNK user since &lt;STRONG&gt;sudo bash&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt; is giving me root user access (ie, whoami shows only root) and &lt;STRONG&gt;su/sudo - splunk&lt;/STRONG&gt; is not working for me in that Linux machine. Is there any other ways I can have SPLUNK user access? Thank you again.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Nov 2021 13:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573909#M10838</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-06T13:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573916#M10839</link>
      <description>&lt;P&gt;That sounds way too overcomplicated. Why do you do it like that? Apps are not meant as a way of uploading files to ingest &lt;span class="lia-unicode-emoji" title=":astonished_face:"&gt;😲&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If your event-generating solution is not on the same host as your HF, why aren't you using UF or sending events via other means (syslog, HEC)?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Nov 2021 17:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/573916#M10839</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-06T17:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574045#M10844</link>
      <description>&lt;P&gt;Yes, it is really very complicated and time consuming......but some of the things we don't control......&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 16:15:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574045#M10844</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-08T16:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574167#M10846</link>
      <description>&lt;P&gt;It's simply confusing since you apparently have CLI access (with permission to run sudo bash ) so you have quite "wide" access to the machine. Furthermore, if you can install apps, you also have quite high-privileged access to the splunk itself. So it's very unusual to do it this way.&lt;/P&gt;&lt;P&gt;There are way more efficient ways to onboard data. Why don't you set the monitor a "static" file or directory and update it periodicaly with scp/sftp/whatever?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 11:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574167#M10846</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-09T11:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574265#M10849</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes, agree!&lt;/P&gt;&lt;P&gt;I can see those events using index=_internal (X OR Y) host=zzzzz, but when I use index=X......I can't...getting error message "Insufficient permission to read file ='/opt/splunk/var/folder. Looks like I can see the events but SPLUNK apps cannot.&amp;nbsp; Thank you so much, any help will be highly appreciated.&lt;/P&gt;&lt;P&gt;In regard to complexity....we receive files from 5 different sources by Email, and then transform them using python scripts based on our requirements, and then pull them into our Linux server using app and then copy from the app folder to&amp;nbsp;/opt/splunk/var/folder.........we are in a process of automatic this system....it's an interim solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 17:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574265#M10849</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-09T17:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574267#M10850</link>
      <description>Sounds like user splunk hasn’t login shell / rights. Can you try sudo -u splunk bash if that is working?</description>
      <pubDate>Tue, 09 Nov 2021 18:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574267#M10850</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-09T18:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574293#M10854</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you ....appreciated......but, &lt;SPAN&gt;&lt;STRONG&gt;sudo -u splunk bash&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;not working.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 21:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574293#M10854</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-09T21:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574537#M10860</link>
      <description>&lt;P&gt;sudo might be restricted to some selected commands. But from the root user it should be possible to&lt;/P&gt;&lt;PRE&gt;su -s /bin/bash splunk&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 10:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574537#M10860</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-11T10:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574541#M10862</link>
      <description>You can see with "sudo -l" what you can do with it.</description>
      <pubDate>Thu, 11 Nov 2021 11:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574541#M10862</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-11T11:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574542#M10863</link>
      <description>&lt;P&gt;If you have to pull the data using a script why not make it into a scripted/modular input and run it from within the splunk&amp;nbsp; service?&lt;/P&gt;&lt;P&gt;That seems more consistent with overall splunk architecture.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 11:17:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574542#M10863</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-11T11:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574606#M10866</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much, it's giving be access as a &lt;STRONG&gt;root&lt;/STRONG&gt; user....but, my issue to get access as &lt;STRONG&gt;splunk&lt;/STRONG&gt; user.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 15:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574606#M10866</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-11T15:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574607#M10867</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes.....it's working as expected...I got the access as a &lt;STRONG&gt;splunk&lt;/STRONG&gt; user.....thank you so much to all of you, appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 15:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574607#M10867</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-11T15:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder cannot forward events</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574610#M10868</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much....Yes, agree....but, we perform transformation process in different server/computer at this stage....and then pull the data using app...as I mentioned.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 15:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-cannot-forward-events/m-p/574610#M10868</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-11-11T15:54:59Z</dc:date>
    </item>
  </channel>
</rss>

