Installation

Why are apps installing as root user when dir is not root owned?

robnewman666
Path Finder

I've set up my Splunk enterprise as a non-root user and up until last week, all apps installed as non privileged user. However, all apps now install as root - and I don't want this to happen - but any ideas why this would have started in the first place? Its only happened on this install with the latest version of Splunk Enterprise - wondering if its a default perhaps? Version is 6.5.0 - has there been any issues with this distro?

Labels (1)
0 Karma
1 Solution

gokadroid
Motivator

Just a shot in the dark but did you check by any chance the last restart of Splunk instance happened as root user?

View solution in original post

0 Karma

gokadroid
Motivator

Just a shot in the dark but did you check by any chance the last restart of Splunk instance happened as root user?

0 Karma

robnewman666
Path Finder

Funny enough, after I wrote the question I did, and yes there was a restart by root, weird though as I did the install as another user and was fine going about my business - then this - also after having a look at some of the Splunk directories, some files seemed to have changed to root owned and now doing a restart with the normal user won't work. Any ideas on why this has happened would be helpful too and how I could reverse it (as a lot of files were changed to root owned). I will have another look tomorrow on this, but i've been trialing a bunch of apps and Splunk Enterprise versions on our test range before we actually use it proper so this is a test and analysis phase. Thanks! 🙂

0 Karma

gokadroid
Motivator

Yw. In such cases, as it did happen to me sometimes, I always do a chown -R splunkUser:splunkUsergroup on the Splunk home directory just to be safe so that all files inside the Home Directory which inadvertently went root to ownership are back to the correct splunkUser ownership.

0 Karma
Get Updates on the Splunk Community!

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...