Getting Data In

What happens when we restart universal forwarder as root user ?

raj_mpl
Path Finder

Hi All,

So , What happens when I restart universal forwarder as root user on Linux . And Previously if done so what needs to be done if anything goes wrong

I am missing one of the log file on a particular host , but remaining logs from different sources are working fine from the same host
So restarted UF as root user ,but didn't worked

Any help ?

Thanks

0 Karma
1 Solution

FrankVl
Ultra Champion

Certain files will change owner, causing stuff to break when you then restart it under the regular user). Solution:

Stop the forwarder (as root)
chown the entire splunk directory to the correct user:group
Start the forwarder (as the correct user)

View solution in original post

0 Karma

FrankVl
Ultra Champion

Certain files will change owner, causing stuff to break when you then restart it under the regular user). Solution:

Stop the forwarder (as root)
chown the entire splunk directory to the correct user:group
Start the forwarder (as the correct user)

0 Karma

raj_mpl
Path Finder

Will that work ? And The missing log from a particular source will start indexing again if I restart the splunk UF as splunk user.

And what the thing called fish bucket .bat files in this scenario?

0 Karma

FrankVl
Ultra Champion

Not sure what the issue was with that specific log that failed to index. But in general, when a splunk instance that used to be running as a normal user, accidentally got restarted as root. What I posted is the solution to get things back to normal.

0 Karma

raj_mpl
Path Finder

Ok @FrankVl , Thanks for your quick response

Thank you 🙂

0 Karma
Get Updates on the Splunk Community!

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...

Splunk Classroom Chronicles: Training Tales and Testimonials

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Access Tokens Page - New & Improved

Splunk Observability Cloud recently launched an improved design for the access tokens page for better ...