Splunk user is unable to read /var/log/audit/audit.log files
Issue
- Getting "permission denied" error when splunk user was trying to read /var/log/audit/audit.log files
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Audit
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.