Installation

Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog

mottycruz
Loves-to-Learn Lots

Hello, I need assistance with Splunkforwarder it Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog. I installed this forwarder as root but server couldn't deployed the apps such as scBaseline_LinuxVarLog, so I decided to installed it under its own users splunk, but now it doesn't have the permissions to create directory here: /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog

I changed the permissions as chown -R splunk:splunk /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog it works momentarily but it change the permissions to root:root again.

Universal Splunkforwarder 8.1 - on Linux machine

Your assistance is appreciated it.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure Splunk is running as splunk?  It sounds like it's still running as root.  How are you starting Splunk and what user are you signed in as at the time?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mottycruz
Loves-to-Learn Lots

after much troubleshooting I deleted /opt/splunkforwarder re-installed UF and things started working again.

Thanks for your support

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...