All,
I have /var/log/messages on a host I want Splunk to be able to read. Here is my log rotation config. Splunk user is working. But cannot read the file even after logrotate runs this rotation.
/var/log/cron
/var/log/maillog
/var/log/messages
/var/log/secure
/var/log/spooler
{
missingok
sharedscripts
postrotate
/bin/kill -HUP cat /var/run/syslogd.pid 2> /dev/null
2> /dev/null || true
/usr/bin/setfacl -m u:splunk:r /var/log/*
endscript
}
If I manually go and run "/usr/bin/setfacl -m u:splunk:r /var/log/*" it works how ever.
Am I missing something?