Deployment Architecture

Splunk attempting to create a Settings directory in root ('/root/.splunk')

jhall0007
Path Finder

I am trying to determine why I am seeing the following error upon reloading the deployment server:

" An error occurred: Could not create Splunk settings directory at '/root/.splunk' "

I think my permissions are correct, but I'm not sure Splunk should be able to write to /root. I was able to find a .splunk hidden file, but it is in my service account's home directory. I am not finding a lot of documentation on the "Splunk settings directory" and how to designate where to place the file - my thought is that this SHOULD be in the home directory rather than root.

I've considered creating a .splunk folder in root owned by my service account but wasn't sure what the far reaching consequences might be.

Little more info on my setup:

  • Using RHEL 6.5 and 6.7
  • Splunk 6.3 (fresh install, not upgraded)
  • My service account running Splunk has admin privileges
  • My service account owns the Splunk directory
  • I use the same service account (sudo su) to reload the deploy-server when I receive the error
  • My service account's Home directory is /home/accoutname

I did see similar trouble reported, but none answering the question of how to configure a different location for the Splunk settings directory:
https://answers.splunk.com/answers/211892/could-not-create-splunk-settings-directory-at-root.html
https://answers.splunk.com/answers/323198/command-for-reloading-the-deployment-server-with-s.html

1 Solution

jhall0007
Path Finder

This trouble was related to partial LDAP configuration. Even though we were using local Splunk credentials (not tied to the LDAP configuration) on the box, it seems the command was reaching out to the AD server and oddly providing the aforementioned error.

View solution in original post

0 Karma

jhall0007
Path Finder

This trouble was related to partial LDAP configuration. Even though we were using local Splunk credentials (not tied to the LDAP configuration) on the box, it seems the command was reaching out to the AD server and oddly providing the aforementioned error.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...