Monitoring Splunk

WARN FilesystemChangeWatcher - error getting attributes of path : Permission denied

tkrishna
New Member

emphasized text
Hi,

      I am trying to send oracle listener log xml files to splunk but i am getting below error . I am able to send /var/log/messages from the same server to splunk 

WARN FilesystemChangeWatcher - error getting attributes of path "/alert": Permission denied

Tags (1)
0 Karma

renjith_nair
Legend

Hi @tkrishna ,

This looks like a file read permission issue.

  • Switch to 'splunk' user and try to read these files.
  • Make sure that the splunk user is able to read parent directories also and execution bit is set on the directory level
  • Run splunk list monitor as splunk user and check if the file is listed.
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

tkrishna
New Member

HI Renjith,

      we don't have spunk user setup. Is it mandatory to have splunk user ? . As i can send /var/log/messages to indexer 
0 Karma

renjith_nair
Legend

Nope, by splunk user I mean whichever user you are using to run splunk , hopefully its not root

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...