Skip to content

Commit 9df2892

Browse files
authored
added setfacl to /etc/logrotate.d/syslog conf Fixes splunk#109 (splunk#152)
1 parent e27e14c commit 9df2892

File tree

2 files changed

+6
-12
lines changed

2 files changed

+6
-12
lines changed

roles/splunk/tasks/configure_facl.yml

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,12 @@
2020
- true
2121
- false
2222

23-
- name: Add logrotate script to enforce splunk user facls
24-
template:
25-
src: splunk_facl.j2
26-
dest: /etc/logrotate.d/splunk_facl
27-
owner: root
28-
group: root
29-
become: true
23+
- name: Add setfacl to logrotate script
24+
lineinfile:
25+
path: /etc/logrotate.d/syslog
26+
insertbefore: ' endscript'
27+
line: ' /usr/bin/setfacl -Rm u:{{ splunk_nix_user }}:rx /var/log'
28+
become: True
3029

3130
- name: Check if auditd.conf is present
3231
stat:

roles/splunk/templates/splunk_facl.j2

Lines changed: 0 additions & 5 deletions
This file was deleted.

0 commit comments

Comments
 (0)