Skip to content

Conversation

@schneewe
Copy link
Contributor

@schneewe schneewe commented Jan 4, 2024

This change allows Splunk to read kernel log and use dmesg even with dmesg_restrict active. Therefore no need to activate for all non-root users

@dtwersky
Copy link
Collaborator

@schneewe There is a configurable var to enable dmesg permissions using sysctl (default disabled), which will be needed if someone is using init.d.

Some people may not want to enable this feature for security purposes.

@schneewe
Copy link
Contributor Author

Yeah that's the reason for this change, because so only Splunk service is allowed to read it, without setting it globally. So no ned to set your var to true.

@jewnix
Copy link
Collaborator

jewnix commented Jan 16, 2025 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants