<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why do I only see the current day's results in searches and should all files in /opt/splunk/var/lib/splunk be owned by root? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-only-see-the-current-day-s-results-in-searches-and/m-p/127092#M34449</link>
    <description>&lt;P&gt;I'm a total splunk newbie, and I inherited a splunk server running on Red Hat Enterprise Linux 5.   The other day, I did a reboot of the system.  Since then, I can only view the current day's data when I run a search.   &lt;/P&gt;

&lt;P&gt;The version of splunk is 5.0.9.  Build 213964 Platform linux x86_64.   The splunkd service is running as root, but when I look in &lt;CODE&gt;/opt/splunk/var/lib/splunk&lt;/CODE&gt;, I see that all the files except for the ones ending in .dat are owned by splunk:splunk.  The .dat files are owned by root:root.  Should they all be owned by root?  &lt;/P&gt;</description>
    <pubDate>Fri, 03 Apr 2015 19:22:50 GMT</pubDate>
    <dc:creator>thadjames</dc:creator>
    <dc:date>2015-04-03T19:22:50Z</dc:date>
    <item>
      <title>Why do I only see the current day's results in searches and should all files in /opt/splunk/var/lib/splunk be owned by root?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-only-see-the-current-day-s-results-in-searches-and/m-p/127092#M34449</link>
      <description>&lt;P&gt;I'm a total splunk newbie, and I inherited a splunk server running on Red Hat Enterprise Linux 5.   The other day, I did a reboot of the system.  Since then, I can only view the current day's data when I run a search.   &lt;/P&gt;

&lt;P&gt;The version of splunk is 5.0.9.  Build 213964 Platform linux x86_64.   The splunkd service is running as root, but when I look in &lt;CODE&gt;/opt/splunk/var/lib/splunk&lt;/CODE&gt;, I see that all the files except for the ones ending in .dat are owned by splunk:splunk.  The .dat files are owned by root:root.  Should they all be owned by root?  &lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2015 19:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-I-only-see-the-current-day-s-results-in-searches-and/m-p/127092#M34449</guid>
      <dc:creator>thadjames</dc:creator>
      <dc:date>2015-04-03T19:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why do I only see the current day's results in searches and should all files in /opt/splunk/var/lib/splunk be owned by root?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-I-only-see-the-current-day-s-results-in-searches-and/m-p/127093#M34450</link>
      <description>&lt;P&gt;You can, but for security purposes, it's not recommended. Best practice is to have a dedicated splunk user account that owns all of the splunk files.  See: &lt;A href="http://wiki.splunk.com/Deploy:EnsuringSplunkRunsAsNonRootUser"&gt;http://wiki.splunk.com/Deploy:EnsuringSplunkRunsAsNonRootUser&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2015 20:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-I-only-see-the-current-day-s-results-in-searches-and/m-p/127093#M34450</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2015-04-03T20:28:47Z</dc:date>
    </item>
  </channel>
</rss>

