Security

Why i'm getting this error???

joseph254
New Member

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

Did not find "disabled" setting of "kvstore" stanza in server bundle.

Splunk> Map. Reduce. Recycle.

Checking prerequisites...

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

Checking mgmt port [8089]: couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

open

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

Checking configuration... Done.

execve: Permission denied

while running command /root/splunk/bin/splunkd

Validating databases (splunkd validatedb) failed with code '8'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue

[root@localhost bin]#

0 Karma

nikita_p
Contributor
0 Karma

dkeck
Influencer

HI,

looks like you got this error on start up, make sure that the user who is running splunk got the ownership of $SPLUNK_HOME/splunk.

you can make sure with running chown -R user:group $SPLUNK_HOME/splunk

What version are you running?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Also look at etc/splunk-launch.conf for SPLUNK_USER - if that's set to splunk but you're trying to run inside /root it'll end in tears.

0 Karma

joseph254
New Member

i solved the problem is due to the permessions which was set to 0644 and i changed it to 0555 !
thank you for help 🙂

0 Karma

dkeck
Influencer

Any luck with that? If it was helpfull please accept the answer, thank you 🙂

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...