Universal Forwarder 9.0.* changing filesystem groups


Hi Forum,

We have an issue with UF 9.0.5. When starting or stopping the filesytem group permissions are changed to the primary group of the technical user running splunk. 

when splunk is started we always see the message:


Warning: Attempting to revert the SPLUNK_HOME ownership
Warning: Executing "chown -R splunk_tech_user /opt/splunkforwarder" 



 This does not  chown  the user but also the group to the primary group of the user. Any chance to skip this? 

Bildschirmfoto 2023-06-16 um 16.37.17.png

version 8.* does not show this issue. 

best regards,


Labels (2)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...