I have installed an app on the forwarder with scripted input.
It's throwing an error while starting Splunk using 'Splunk' user
11/9/20
9:13:20.631 PM
11-09-2020 21:13:20.631 +0000 ERROR ExecProcessor - message from "/opt/splunkforwarder/etc/apps/AWSMData/bin/awsmeta.sh" /bin/sh: /opt/splunkforwarder/etc/apps/AWSMetaData/bin/awsmetarun.sh: Permission denied
host = host.ip.internalindex = _internalsource = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd
11/9/20
I tried to set the permission to this script located under SPLUNK_HOME/etc/apps/<appname>/bin/<script>
But whenever i restart Splunk daemon, the permission revokes
Hi @hpmist198 ,
Can you please check what ownership is assign to Splunk? If proper ownership is not assigned to your path of Splunk, you can give proper permission by running the command
chown -R splunk:splunk /opt/splunk
--------------------------------------------------------
If this helps your like will be appreciated 😀
Yes ownership and permission looks ok for me. It's owned by splunk user and group.