Splunk Enterprise

splunkforwarder stopped forwarding to indexer after ACL change on FS

bhupalbobbadi
Path Finder

I've singe SPF forwarding to 3 indexers in a cluster, after changing the file permissions to rw from rwx the splunk forwarder stopped indexing files from input dirs. have seen logs no clues found. Any suggestions when to look for errors/exceptions. TIA.

Tags (1)
0 Karma

wmyersas
Builder

Directories have to be executable in order to do anything inside them

It's the nature of *nix permissioning

0 Karma

sumanssah
Communicator

I assume the directories that were changes may be owned by root permissions. I would suggest you make the following changes

As root user run the following command:

chown -R splunk:splunk /opt/splunk/
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...