Security

ERROR BTreeCP ~~~~ \snapshot.old: Access is denied. error

cjsweeney1
Explorer

Getting this error on a few systems...

08-28-2016 22:03:18.924 -0400 ERROR BTreeCP  - failed: failed to rename C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db\snapshot to C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db\snapshot.old: Access is denied. 

Anyone know what file and setting I should be looking at for the fix? It seems like a authentication.conf (I'm setup for LDAP authentication) setting reference and just wanted an opinion. Thanks.

ololdach
Builder

Hello,

could it be that you are running the forwarder as a non-privileged user? If so, you could change the ownership of the splunkhome\var directory tree to the splunk user.

Oliver

0 Karma

camigirl4k3
Engager

I have the same issue with my account. I'm trying to change the authentication.conf file to include some group mappings and it says I can't save. I am administrator on this machine...so is it because the service is still running?

0 Karma

vr2312
Builder

Hello @cjsweeney1

It seems the account Splunk is being run in the Windows Server does not have the admin privileges to remove the snapshot,old file from the location.

Once the privileges are updated, Splunk would have permission to edit the file and rename it to what is required.

We had this addressed by ensuring the permissions splunk is using in the host are updated.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...