Hi team, I am unable to send logs to server by using "splunk add monitor <filename>" command with forwarder version 9.4.0 Splunk is running as root user. add monitor command is asking for credentials. And the inputs.conf file is not getting updated with the log file name that is added to monitor. sudo splunk add monitor Test.log Warning: Attempting to revert the SPLUNK_HOME ownership Warning: Executing "chown -R root:root /opt/splunkforwarder" Splunk username: Password: Login failed Tested with forwarder version 9.0.0 and it worked. That time also it asked for credentials but inputs.conf got updated and logs sent to server without providing the credentials. I want to send logs to server using forwarder 9.4.0 What changes should I do to make it work. Please suggest...
... View more