- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good Morning I'm trying to download splunk and start it on my terminal but I keep getting this error code:
Exception: <class 'PermissionError'>, Value: [Errno 13] Permission denied: '/opt/splunk/etc/system/local/eventtypes.conf.tmp'
PermissionError: [Errno 13] Permission denied: '/opt/splunk/etc/system/local/eventtypes.conf.tmp'
please help!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/0006d/0006db53e93e02f75a70b791d53de4db2c1334ef" alt="gcusello gcusello"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
Hi @SamuraP ,
let me understand:
I suppose that you want to texecute Splunk as user Splunk
as you can read at https://docs.splunk.com/Documentation/Splunk/9.0.4/Installation/InstallonLinux and https://docs.splunk.com/Documentation/Splunk/9.0.4/Installation/RunSplunkasadifferentornon-rootuser , the Splunk installation procedure on linux says:
- copy files (using rpm or tar) on the system,
- useradd splunk
- groupadd splunk
- chown -R splunk:splunk $SPLUNK_HOME
- su - splunk
- cd /opt/splunk/bin/
- run ./splunk start --accept-license,
- then at the end enable boot start using the command you used: ./splunk enable boot-start -user Splunk
Did you followed this path?
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just did this and it works! But when I try to access Splunk instances by using my IP address from the AWS it doesn't work. This is the Command I'm trying http://<your public ip>:8000.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/0006d/0006db53e93e02f75a70b791d53de4db2c1334ef" alt="gcusello gcusello"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
Hi @SamuraP ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/0006d/0006db53e93e02f75a70b791d53de4db2c1334ef" alt="gcusello gcusello"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
Hi @SamuraP,
a stupid question: did you disabled firewalld (iptables) from your system?
obviously I suppose that you checked that Splunk is running with "/opt/splunk/bin/splunk status"
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/0006d/0006db53e93e02f75a70b791d53de4db2c1334ef" alt="gcusello gcusello"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did this command ./splunk enable boot-start -user Splunk. and then I accepted the license ut I guess since I had an old version it asked me if I wanted to upgrade and I said yes then it gave me the error.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/0006d/0006db53e93e02f75a70b791d53de4db2c1334ef" alt="gcusello gcusello"
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
Hi @SamuraP ,
let me understand:
I suppose that you want to texecute Splunk as user Splunk
as you can read at https://docs.splunk.com/Documentation/Splunk/9.0.4/Installation/InstallonLinux and https://docs.splunk.com/Documentation/Splunk/9.0.4/Installation/RunSplunkasadifferentornon-rootuser , the Splunk installation procedure on linux says:
- copy files (using rpm or tar) on the system,
- useradd splunk
- groupadd splunk
- chown -R splunk:splunk $SPLUNK_HOME
- su - splunk
- cd /opt/splunk/bin/
- run ./splunk start --accept-license,
- then at the end enable boot start using the command you used: ./splunk enable boot-start -user Splunk
Did you followed this path?
Ciao.
Giuseppe
data:image/s3,"s3://crabby-images/a266d/a266d0c80c12793a952b209c17cc3de41b17fc89" alt=""