<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunkfwd user modifying /etc/passwd in Installation</title>
    <link>https://community.splunk.com/t5/Installation/splunkfwd-user-modifying-etc-passwd/m-p/677333#M13626</link>
    <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;P&gt;How are you doing?&lt;BR /&gt;Our FIM tool is detecting modifications to the /etc/passwd file by the splunkfwd user found on some of our critical Linux servers for our operation with Splunk Universal Forwarder installed.&lt;BR /&gt;Do you know if this behavior is correct? Shouldn't it be modifying /opt/splunkforwarder/etc/passwd?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;BR /&gt;Regards,&lt;BR /&gt;Juanma&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: when echoing $SPLUNK_HOME it appears to be blank in other users, but the tools is sending logs correctly to SplunkCloud&lt;/P&gt;</description>
    <pubDate>Mon, 12 Feb 2024 20:15:04 GMT</pubDate>
    <dc:creator>jalbarracinklar</dc:creator>
    <dc:date>2024-02-12T20:15:04Z</dc:date>
    <item>
      <title>splunkfwd user modifying /etc/passwd</title>
      <link>https://community.splunk.com/t5/Installation/splunkfwd-user-modifying-etc-passwd/m-p/677333#M13626</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;P&gt;How are you doing?&lt;BR /&gt;Our FIM tool is detecting modifications to the /etc/passwd file by the splunkfwd user found on some of our critical Linux servers for our operation with Splunk Universal Forwarder installed.&lt;BR /&gt;Do you know if this behavior is correct? Shouldn't it be modifying /opt/splunkforwarder/etc/passwd?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;BR /&gt;Regards,&lt;BR /&gt;Juanma&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: when echoing $SPLUNK_HOME it appears to be blank in other users, but the tools is sending logs correctly to SplunkCloud&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 20:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunkfwd-user-modifying-etc-passwd/m-p/677333#M13626</guid>
      <dc:creator>jalbarracinklar</dc:creator>
      <dc:date>2024-02-12T20:15:04Z</dc:date>
    </item>
  </channel>
</rss>

