Hi @valderrama, unfortunately we don't have the flexibility to write logs as a user other than the user running osqueryd, but we do restrict the read access as sensitive information is included in the results logs. You can use logrotate or newsyslog to move the logs to another user's ownership or run Splunk as root (eww, I know)