Getting Data In

Permissions for Linux forwarder on .gz log files

apache_strike
Engager

Hi everyone,

I want to monitor files on a Linux server. Every hours (at minute 59), a file DATE.log is compressed into a DATE.gz.

Though inputs.conf I am monitoring all the files (DATE*). I noticed that I have some logs missing for 20 minutes (from ~ the minute 37 to the minute 59) every hours between 8am to 8pm. I checked the splunkd.log and saw this error:

WARN TailReader - Insufficient permissions to read file='.../DATE.gz' (hint: Permission denied)

I gave reading rights on the .gz files, but maybe it's not enough as the decompression is effective on the forwarder. Should I give writing rights to my splunk user on these files?

Not sure if it's gonna fix the missing logs problem but I will start with that ^^

Have a good day,

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...