<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=us-ascii" http-equiv=Content-Type>
<META name=GENERATOR content="MSHTML 9.00.8112.16696"></HEAD>
<BODY>
<DIV dir=ltr align=left><SPAN class=051374815-14092015><FONT size=2
face=Arial>Have you restarted the xymon client? Changes to linux group
memberships on apply to new logins...</FONT></SPAN></DIV><!-- Converted from text/rtf format -->
<P align=left><SPAN lang=en-gb><FONT size=2 face=Arial>Kind
regards,</FONT></SPAN> </P>
<P><SPAN lang=en-gb><FONT size=2 face=Arial>Seb<SPAN
class=051374815-14092015>A</SPAN> </FONT></SPAN> <BR></P>
<DIV> </DIV><BR>
<BLOCKQUOTE
style="BORDER-LEFT: #000000 2px solid; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; MARGIN-RIGHT: 0px"
dir=ltr>
<DIV dir=ltr lang=en-us class=OutlookMessageHeader align=left>
<HR tabIndex=-1>
<FONT size=2 face=Tahoma><B>From:</B> Elizabeth Jones
[mailto:oogiejonz@yahoo.com] <BR><B>Sent:</B> 14 September 2015
16:36<BR><B>To:</B> xymon@xymon.com<BR><B>Subject:</B> reading
/var/log/messages<BR></FONT><BR></DIV>
<DIV></DIV>
<DIV
style="BACKGROUND-COLOR: #fff; FONT-FAMILY: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; COLOR: #000; FONT-SIZE: 16px">We
just set up splunk in our environment and have made all our /var/log/messages
owned by root:splunk mode 640 so that splunk can read and index these
files. I was thinking I could add xymon user to splunk group and that
would allow xymon to read /var/log/messages as well, but it doesn't seem to be
working. I can read /var/log/messages as the xymon user but the msgs web
page is still showing <BR><PRE id=yui_3_16_0_1_1442244748758_2576>Cannot open logfile /var/log/messages : Permission denied</PRE>
<DIV id=yui_3_16_0_1_1442244748758_2494>Any ideas on what else I can do to
allow xymon to get these logs?<BR></DIV></DIV></BLOCKQUOTE></BODY></HTML>