Installation

Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog

mottycruz
Loves-to-Learn Lots

Hello, I need assistance with Splunkforwarder it Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog. I installed this forwarder as root but server couldn't deployed the apps such as scBaseline_LinuxVarLog, so I decided to installed it under its own users splunk, but now it doesn't have the permissions to create directory here: /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog

I changed the permissions as chown -R splunk:splunk /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog it works momentarily but it change the permissions to root:root again.

Universal Splunkforwarder 8.1 - on Linux machine

Your assistance is appreciated it.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure Splunk is running as splunk?  It sounds like it's still running as root.  How are you starting Splunk and what user are you signed in as at the time?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mottycruz
Loves-to-Learn Lots

after much troubleshooting I deleted /opt/splunkforwarder re-installed UF and things started working again.

Thanks for your support

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...