Documentation:
3.3
If you have SELinux active on your system, you must add Splunk to the list of authenticated applications that can run in your SELinux environment.
To configure SELinux to allow Splunk to run, you need to run the
chcon command on the Splunk lib directory. Here is what you type :
chcon -c -v -R -u system_u -r object_r -t lib_t $SPLUNK_HOME/lib 2>&1 > /dev/null
You must also disable the check when Splunk starts by adding this line
to $SPLUNK_HOME/etc/splunk-launch.conf.
SPLUNK_IGNORE_SELINUX=1
Comments
thank you, meeas. i've updated the topic.
Posted by rachel on Mar 10 2008, 2:22pm
Don't put "export" in front of "SPLUNK_IGNORE_SELINUX=1" in splunk-launch.conf. Just set the variable to "1".
This was an artifact from the previous 3.1.5 documentation that they missed.
Posted by meeas on Mar 08 2008, 4:01pm