Monitoring Splunk

Why are splunk binaries creating under /usr/bin automatically?

venkateshparank
Path Finder

We had an EC2 instance become inaccessible via the AWS Session Manager.

Root cause was the main volume filling-up with various splunkfowarder-x.x.x RPM files in /usr/bin/

Yesterday the filesystem was cleaned-up, but today there's another copy of that RPM in the /usr/bin/ directory.

Does anyone know why is this happening ?

0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Most probably some automatic tool keeps downloading said package files onto your machine. What is it and why it does that - I have no idea. Did you check who owns those files? Splunk Enterprise or Universal Forwarder unless hurt very badly by some misadministration don't touch /usr/bin on their own.

View solution in original post

0 Karma

venkateshparank
Path Finder

There was an automation in backend within AWS AMI to install older version.

That was the issue and we are able to update the backend code.

Thank you for the response

richgalloway
SplunkTrust
SplunkTrust

Splunk does nothing with the /usr/bin directory (or anything outside of $SPLUNK_HOME and $SPLUNK_DB, for that matter*) so something other than Splunk is putting the files there.

It might be a good idea to use Splunk to monitor disk space and send an alert when it becomes critically low.

* Scripts configured to run in Splunk can touch any files or directories with the right permissions, of course.  It's not Best Practice, but is done in some sites.  You may have a script running (in Splunk or not) that is trying to refresh the UF

---
If this reply helps you, Karma would be appreciated.

PickleRick
SplunkTrust
SplunkTrust

Most probably some automatic tool keeps downloading said package files onto your machine. What is it and why it does that - I have no idea. Did you check who owns those files? Splunk Enterprise or Universal Forwarder unless hurt very badly by some misadministration don't touch /usr/bin on their own.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...