Getting Data In

Deployed app on Universal Forwarder being created with 700 permissions (Linux Deployment Server to Linux UF)

twhitehead
New Member

Created an app on the deployment server which is used to tell the Universal Forwarder which directories and logs to monitor. There is no issue with this aspect, the logs are being monitored as expected.

What I would like to do is setup permissions on the Universal Forwarder so that other groups can read/write to the directories that are created by the UF.

  • Used RPM to install to /opt/splunkforwarder
  • splunk:splunkis used to own the files and run the service
  • setgid is configured on /opt/splunkforwarder
  • Setup File ACL permissions along with some defaults

    # file: opt/splunkforwarder/

    owner: splunk

    group: splunk

    flags: -s-

    user::rwx
    group::rwx
    group:splunk:rwx
    mask::rwx
    other::r-x
    default:user::rwx
    default:group::rwx
    default:group:splunk:rwx
    default:mask::rwx
    default:other::r-x

However when an app is deployed to the UF, the mask is not set on the ACL stripping the newly created directory of the group permissions.

Access: (2700/drwx--S---) Uid: ( 205/ splunk) Gid: ( 205/ splunk)

# file: myapp/
# owner: splunk
# group: splunk
# flags: -s-
user::rwx
group::rwx        #effective:---
group:splunk:rwx  #effective:---
mask::---
other::---
default:user::rwx
default:group::rwx
default:group:splunk:rwx
default:mask::rwx
default:other::r-x

Logging in interactively or non-interactive, the directories is created with the expected permissions.
Access: (2775/drwxrwsr-x) Uid: ( 205/ splunk) Gid: ( 205/ splunk)

# file: test/
# owner: splunk
# group: splunk
# flags: -s-
user::rwx
group::rwx
group:splunk:rwx
mask::rwx
other::r-x
default:user::rwx
default:group::rwx
default:group:splunk:rwx
default:mask::rwx
default:other::r-x

I can manually add the mask sudo setfacl -Rm m:rwX myapp/and the effective permissions will be as intended.
Access: (2770/drwxrws---) Uid: ( 205/ splunk) Gid: ( 205/ splunk)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...