Hi @alex12 As documented here https://docs.splunk.com/Documentation/Forwarder/9.3.1/Forwarder/Installleastprivileged the CAP_DAC_READ_SEARCH will work only with UF (not with HF) the HF installation method (regular Splunk enterprise installation) https://docs.splunk.com/Documentation/Splunk/9.3.1/Installation/InstallonLinux
... View more