Getting Data In

Restarting Splunk in the serverclass.conf

mocallaghan
Engager

I have question on restarting a Splunk Forwarder when rolling out a new app. In the serverclass.conf file, I'm adding a new app to an existing forwarder. Elsewhere in the serverclass.conf, the forwarder belongs to a server class that contains the restartSplunkd = true statement. When Splunk restarts on the forwarder, what user will it start with? I would like it to restart with a user named splunk, since we have a non-root user running splunk. If I've enabled splunk to restart on boot with a non-root user, will it use that user to start splunk? Any help is greatly appreciated!

Tags (1)
0 Karma

jgedeon120
Contributor

Splunk should restart with the user that you have it configured to run as when you did the install and enabled the boot start.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...