Deployment Architecture

Could not create Splunk settings directory at '/root/.splunk'

jizzmaster
Path Finder

Anytime I try to do anything with my deployment server I get this error:

An error occurred: Could not create Splunk settings directory at '/root/.splunk'

This includes the commands: splunk display deploy-server, splunk display deploy-client, and splunk reload deploy-server. I'm taking this over for another and not sure when it last worked.

Also, it kinda works. I deployed an app with it. However, I can tell there's a problem here and want to fix this.

The /root/.splunk exists. I tried deleting it, same error. I tried creating it and giving the splunk user access to it, no go. This is on a RHEL6 box, by the way. I've also restarted splunk and the same error occurs.

1 Solution

chanfoli
Builder

Yeah, I noticed some funky permissions issues executing commands which use auth sessions as the root user after upgrading from splunk 6.1 to 6.2. It looks like this is because splunkd is running as a non-root user then tries to store some auth session info or the like under the current user's home. I decided to change my practice and execute splunk CLI commands against running splunk as the splunk user and I stopped seeing such errors.

View solution in original post

jhall0007
Path Finder

Were you ever able to resolve this issue?

I am also seeing the same error on a RHEL deployment server. I am suspecting Splunk should be creating the .splunk hidden file in the home directory instead of root. However, I am finding difficulty determining where this was incorrectly configured.

I am running Splunk 6.3
I am using the same account to run Splunk as execute the reload "deploy-server command"
I am running the command from sudo
The account's home is /home/accountname

0 Karma

chanfoli
Builder

Yeah, I noticed some funky permissions issues executing commands which use auth sessions as the root user after upgrading from splunk 6.1 to 6.2. It looks like this is because splunkd is running as a non-root user then tries to store some auth session info or the like under the current user's home. I decided to change my practice and execute splunk CLI commands against running splunk as the splunk user and I stopped seeing such errors.

cboillot
Contributor

I just ran into this issue and what I did was as superuser, made the '/root/.splunk' directory and changed the owner to splunk

jrodman
Splunk Employee
Splunk Employee

I believe that specific problem is resolved in 6.2.1.

0 Karma

landen99
Motivator

I just encountered the error so it is obviously not resolved yet.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...