A new splunk user here.
I am trying to install splunk UF on ubuntu. I get this error while trying to run the package for the first time:
Could not open log file "/opt/splunkforwarder/var/log/splunk/first_install.log" for writing (2).
I saw some articles online but the suggestions did not resolve the issue for me.
If I can get some step by step guide on resolving this, I will be grateful.
Thank you.
It would help to know what "suggestions" you've tried already, but it appears as though the file permissions are incorrect. Make sure all files in /opt/splunk are owned by user 'splunk' (or another non-root user that will be running the UF).