Security

Receiving this warning: "cannot create "/opt/splunk/var/log/watchdog"

dataops
Engager

Why am I receieving this error?

Warning: cannot create "/opt/splunk/var/log/watchdog"

Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
Pid file "/opt/splunk/var/run/splunk/splunkd.pid" unreadable.: Permission denied
0 Karma

richgalloway
SplunkTrust
SplunkTrust

This can happen if Splunk is run as root and then run as a non-root user without changing the ownership of all files in /opt/splunk.

---
If this reply helps you, Karma would be appreciated.

codebuilder
Influencer

Agree with Rich, I've seen this behavior in the very same circumstances.

chown the pid file to the user running splunk.
e.g.
chown splunk:splunk /opt/splunk/var/run/splunk/splunkd.pid
cycle splunk

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

Anam
Community Manager
Community Manager

Hi @dataops

Thank you for posting your question on Splunk Answers. In order for experts to help you, can you please provide more information in context that resulted in you seeing this error? Were you making changes to the authorize.conf file?

Thanks

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...