Deployment Architecture

When your universal forwarder runs as root, should all of your apps run as root?

campbellj1977
Explorer

If so, does that mean your deployment server should run as root also? It keeps deploying client apps as "splunk"

0 Karma

dflodstrom
Builder

Best practice is to run splunk as a user other than root.

If your universal forwarder is running with root/admin privileges you shouldn't have any issues with communication between it and your indexer.

Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...