Hi Mike,
I had checked with my concerned team to provide the read privileges, but as per the security limitations they are not ready to provide the read access.
For version 6.0 I am able to start and stop the splunk and it is not referring to /etc/inittab and has the same permissions.
But in the version 6.2.2 it is referring to /etc/inittab. Is there any way that we can modify the splunkd files which is referring the inittab and can disable it.
Could you please let me know, If there is any way with out modifying the permissions of /etc/inittab and using the splunk.
... View more