Is there any way to find out which user/service account is running the splunk services on linux?
I am looking to collect this information from all the forwarders (deployed on servers owned by different teams) to ensure correct service accounts are used to start/restart splunk service.
I did go through the Splunk's internal logs on _internal and _audit index but couldn't find the user reference during a service(splunkd) restart. Any pointer to a linux command/shell script/splunk logs should be helpful.
We don't run Nix app as its little bit heavy app generating lot of data which we don't need. We use parts of it. Based on your suggestion on ps command, I wrote following command to get required information for Splunk related processes.