Getting Data In

Spot permissions denied errors- How could I spot this issue in the first place ?

GaetanVP
Contributor

Hello Splunkers,

I faced the following issue :

I deployed an app on a UF, this app should monitor a specific file in my machine let's say /<my_file>

The thing is I'm running Splunk service as a non root user (splunk user) and this user does not have permission to read this file. I know how to solve this with setfacl command, but how could I spot this issue in the first place ?

I thought that this permission error would have been visible in splunkd.log but it's not the case... I am trying to find a way to monitor the other possible "permissions denied" errors without manually log in as the splunk user and try to open the specific files.

Thanks a lot,

GaetanVP

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

you can search "permission denied" in _internal index for that host in Splunk Search & Reporting App.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

you can search "permission denied" in _internal index for that host in Splunk Search & Reporting App.

Ciao.

Giuseppe

GaetanVP
Contributor

Hello @gcusello,

Good guess, I indeed have "Permission denied" in some WARN message (failed to open for checksum - for a .gz file)

But I also have the following string "Reason: cannot_open" (this time it is for a single file) 

I suppose there is different string to search based on the type of files / folder, but your answer helped, thanks !

GaetanVP

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...