Getting Data In

Splunk - openshift DaemonSet deployment error

ayush-choudhary
Explorer

I was trying to get DaemonSet up and running

got below errors while getting pods ready

[error]: #0 unexpected error error_class=Errno::EACCES error="Permission denied @ rb_sysopen - /var/log/splunk-fluentd-kube-audit.pos"
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/plugin/in_tail.rb:241:in `initialize'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/plugin/in_tail.rb:241:in `open'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/plugin/in_tail.rb:241:in `start'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:203:in `block in start'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:192:in `block (2 levels) in lifecycle'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:191:in `each'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:191:in `block in lifecycle'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:178:in `each'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:178:in `lifecycle'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/root_agent.rb:202:in `start'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/engine.rb:248:in `start'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/engine.rb:147:in `run'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/supervisor.rb:717:in `block in run_worker'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/supervisor.rb:968:in `main_process'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/supervisor.rb:708:in `run_worker'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/lib/fluent/command/fluentd.rb:372:in `<top (required)>'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/bin/fluentd:15:in `require'
0 [error]: #0 /usr/share/gems/gems/fluentd-1.14.2/bin/fluentd:15:in `<top (required)>'
0 [error]: #0 /usr/bin/fluentd:23:in `load'
0 [error]: #0 /usr/bin/fluentd:23:in `<main>'
[error]: #0 unexpected error error_class=Errno::EACCES error="Permission denied @ rb_sysopen - /var/log/splunk-fluentd-kube-audit.pos"
0 [error]: #0 suppressed same stacktrace

Labels (1)
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...