Getting Data In

Installing rpm as different user and not creating splunk user

aaronkorn
Splunk Employee
Splunk Employee

Is it possible to install the universal forwarder rpm as a different user and not have the rpm create the "splunk" user?

0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

In this scenario I'd usually use the tarball to install Splunk

Does that option work for you?

View solution in original post

dart
Splunk Employee
Splunk Employee

In this scenario I'd usually use the tarball to install Splunk

Does that option work for you?

aaronkorn
Splunk Employee
Splunk Employee

Thank you both for your contributions. This will work for me.

0 Karma

kristian_kolb
Ultra Champion

Hm, I guess it would be possible to:

a) install the rpm
b) chown all files in /opt/splunkforwarder
c) delete the 'splunk' user account
d) create the init.d script to run splunk with the user of your choice.

However, I have not tried this, and I'm also unsure if it would survive an upgrade.

Or if you download the tgz instead of rpm, it won't create any accounts, AFAIK.

/Kristian

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...