Hello, I need assistance with Splunkforwarder it Cannot create parent directory /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog. I installed this forwarder as root but server couldn't deployed the apps such as scBaseline_LinuxVarLog, so I decided to installed it under its own users splunk, but now it doesn't have the permissions to create directory here: /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog
I changed the permissions as chown -R splunk:splunk /opt/Splunkforward/etc/apps/scBaseline_LinuxVarLog it works momentarily but it change the permissions to root:root again.
Universal Splunkforwarder 8.1 - on Linux machine
Your assistance is appreciated it.
Are you sure Splunk is running as splunk? It sounds like it's still running as root. How are you starting Splunk and what user are you signed in as at the time?
after much troubleshooting I deleted /opt/splunkforwarder re-installed UF and things started working again.
Thanks for your support