Security

Why i'm getting this error???

joseph254
New Member

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

Did not find "disabled" setting of "kvstore" stanza in server bundle.

Splunk> Map. Reduce. Recycle.

Checking prerequisites...

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

Checking mgmt port [8089]: couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

open

couldn't run "/root/splunk/bin/splunkd" "btool": Permission denied

Checking configuration... Done.

execve: Permission denied

while running command /root/splunk/bin/splunkd

Validating databases (splunkd validatedb) failed with code '8'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue

[root@localhost bin]#

0 Karma

nikita_p
Contributor
0 Karma

dkeck
Influencer

HI,

looks like you got this error on start up, make sure that the user who is running splunk got the ownership of $SPLUNK_HOME/splunk.

you can make sure with running chown -R user:group $SPLUNK_HOME/splunk

What version are you running?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Also look at etc/splunk-launch.conf for SPLUNK_USER - if that's set to splunk but you're trying to run inside /root it'll end in tears.

0 Karma

joseph254
New Member

i solved the problem is due to the permessions which was set to 0644 and i changed it to 0555 !
thank you for help 🙂

0 Karma

dkeck
Influencer

Any luck with that? If it was helpfull please accept the answer, thank you 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...