<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to properly setup splunkforwarder in CentOS 6.8 in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-properly-setup-splunkforwarder-in-CentOS-6-8/m-p/321017#M2964</link>
    <description>&lt;P&gt;Use the same commands to start, stop or restart Splunk - regardless of whether it is a forwarder, an indexer or any other kind of Splunk instance:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunkforwarder/bin/splunk start
/opt/splunkforwarder/bin/splunk stop
/opt/splunkforwarder/bin/splunk restart
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, be sure that you are using the right user account to start Splunk. For example, if you created a user account named "splunkIT" to run the forwarder, be sure that you use that account to run the start command. And all the files in the /opt/splunkforwarder directory (and subdirectories) must be owned by "splunkIT" - or whatever account that you used.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2017 07:43:11 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2017-02-22T07:43:11Z</dc:date>
    <item>
      <title>How to properly setup splunkforwarder in CentOS 6.8</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-properly-setup-splunkforwarder-in-CentOS-6-8/m-p/321016#M2963</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I'm trying to setup splunkforwarder in a new Linux server (CentOS 6.8), but every time I try to run splunkd, I get the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# /opt/splunkforwarder/bin/splunkd
Couldn't open log file configuration "/etc/log.cfg": No such file or directory
Error loading logging config file
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The problem is, the "log.cfg" file is currently contained within the path "/opt/splunkforwarder/etc/log.cfg" and I couldn't find a way to fix splunkd in order to make it look within "/opt/splunkforwarder/etc/" instead of "/etc/".&lt;/P&gt;

&lt;P&gt;Any advice? I couldn't find the documentation to do it properly. Please let me know if there is a proper standard way to fix it, I don't want to reinvent the wheel.&lt;/P&gt;

&lt;P&gt;Thanks in advance. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 15:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-properly-setup-splunkforwarder-in-CentOS-6-8/m-p/321016#M2963</guid>
      <dc:creator>ggs_admin</dc:creator>
      <dc:date>2017-02-21T15:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly setup splunkforwarder in CentOS 6.8</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-properly-setup-splunkforwarder-in-CentOS-6-8/m-p/321017#M2964</link>
      <description>&lt;P&gt;Use the same commands to start, stop or restart Splunk - regardless of whether it is a forwarder, an indexer or any other kind of Splunk instance:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunkforwarder/bin/splunk start
/opt/splunkforwarder/bin/splunk stop
/opt/splunkforwarder/bin/splunk restart
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, be sure that you are using the right user account to start Splunk. For example, if you created a user account named "splunkIT" to run the forwarder, be sure that you use that account to run the start command. And all the files in the /opt/splunkforwarder directory (and subdirectories) must be owned by "splunkIT" - or whatever account that you used.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 07:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-properly-setup-splunkforwarder-in-CentOS-6-8/m-p/321017#M2964</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-02-22T07:43:11Z</dc:date>
    </item>
  </channel>
</rss>

