Getting Data In

Why does Splunk service startup change permissions on outputs.conf to read only on my Windows universal forwarder?

rob_gibson
Path Finder

I am deploying new certificates to a number of UF's running on Windows Servers 2008 R2. This environment is restricted and I do not have admin rights on the server. Prior to the steps below I have full rights to the $SPLUNK_HOME directory and sub dirs.

During this process I stop the Splunk Universal Forwarder service, rename the existing outputs.conf to outputs.old and copy a new outputs.conf from a network share, then restart the UF service (as well as copying new cert files).

After starting splunk, the permissions (not file attributes) change from RW to Read only and I no longer have access to edit outputs.conf.

Is this expected behaviour and can I stop this from happening? I realize I can edit the existing outputs.conf file vs replacing it, but I would like to stop splunk from setting permissions at all.

0 Karma

lycollicott
Motivator

This is just a shot in the dark, but your Windows admins might have GPO doing something when services restart.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...