Installation

Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog

mottycruz
Loves-to-Learn Lots

Hello, I need assistance with Splunkforwarder it Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog. I installed this forwarder as root but server couldn't deployed the apps such as scBaseline_LinuxVarLog, so I decided to installed it under its own users splunk, but now it doesn't have the permissions to create directory here: /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog

I changed the permissions as chown -R splunk:splunk /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog it works momentarily but it change the permissions to root:root again.

Universal Splunkforwarder 8.1 - on Linux machine

Your assistance is appreciated it.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure Splunk is running as splunk?  It sounds like it's still running as root.  How are you starting Splunk and what user are you signed in as at the time?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mottycruz
Loves-to-Learn Lots

after much troubleshooting I deleted /opt/splunkforwarder re-installed UF and things started working again.

Thanks for your support

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...