I am running the command
sudo -u splunk ./splunk add monitor /var/log/
When I do this, I receive the error 'Can't create directory "/home/myusername/.splunk": Permission denied.' Seeing as the command is being run as the splunk user, I can't see why it would be trying to make a directory in my home directory. Why is this happening, and how can I fix it?
When you start your forwarder do you run the init or call the program via the splunk user or the root user?. My guess would be that you called it form root and your permissions are for the root user. If you do an ls -la you can see who owns the files. I would approach the problem as user root run chown -R splunk:splunk /opt/splunkforwarder/ then ensure you start the forwarder as splunk. Your sudo -u splunk should now be able to make the necessary changes.