<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Unix and Linux errors with configuration in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160546#M14843</link>
    <description>&lt;P&gt;The problem is that the SA-nix and/or Splunk_TA_nix aren't being installed properly.  You might have more than 30 apps on your system and be running Splunk 6.1.   The workaround is to copy SA-nix and Splunk_TA_nix from splunk_app_for_nix/install into your $SPLUNK_HOME/etc/apps directory and restart Splunk.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:11:51 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2020-09-28T17:11:51Z</dc:date>
    <item>
      <title>Splunk App for Unix and Linux errors with configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160545#M14842</link>
      <description>&lt;P&gt;I've just installed the Splunk App for *Nix. The indexer/forwarder that it is on is Windows based, running splunk 6. I have 1 redhat linux box configured with the add-on and the universal forwarder to send to this box. When I navigate to the Splunk for Nix app, i get the following error messages:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;The lookup table 'nix_action_lookup' does not exist. It is referenced by configuration 'syslog'.&lt;/P&gt;

&lt;P&gt;The lookup table 'nix_action_lookup' does not exist. It is referenced by configuration 'osx_secure'.&lt;/P&gt;

&lt;P&gt;The lookup table 'nix_action_lookup' does not exist. It is referenced by configuration 'linux_secure'.&lt;/P&gt;

&lt;P&gt;The lookup table 'nix_action_lookup' does not exist. It is referenced by configuration 'aix_secure'.&lt;/P&gt;

&lt;P&gt;The lookup table 'linux_service_startmode_lookup' does not exist. It is referenced by configuration 'source::...(Linux|Unix):Service'.&lt;/P&gt;

&lt;P&gt;The lookup table 'fs_notification_change_type_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;/P&gt;

&lt;P&gt;The lookup table 'endpoint_change_vendor_action_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;/P&gt;

&lt;P&gt;The lookup table 'endpoint_change_status_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;/P&gt;

&lt;P&gt;The lookup table 'endpoint_change_object_category_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;/P&gt;

&lt;P&gt;The lookup table 'da_version_range_lookup' does not exist. It is referenced by configuration 'source::...(AIX|FreeBSD|HPUX|Linux|OSX|Solaris|Unix):Version'.&lt;/P&gt;

&lt;P&gt;The lookup table 'da_update_status_lookup' does not exist. It is referenced by configuration 'source::...(AIX|FreeBSD|HPUX|Linux|OSX|Solaris|Unix):Update'.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Here's a screenshot (i62.tinypic.com/1qo310.png) of the error.&lt;/P&gt;

&lt;P&gt;A bit of googling around hasn't shown me anything useful. I've re-installed twice and am still having the same issue.&lt;BR /&gt;
The installation and configuration instructions are a bit fuzzy on some details, so maybe I'm missing something. &lt;BR /&gt;
Also, instructions talk about configuring the Add-on on the search head/indexer. When trying to set it up I get an error message telling me that since its not on linux/unix there are no config options available.&lt;/P&gt;

&lt;P&gt;Can anyone tell me what I'm missing here? I'm a bit stumped.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160545#M14842</guid>
      <dc:creator>blindauer</dc:creator>
      <dc:date>2020-09-28T17:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Unix and Linux errors with configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160546#M14843</link>
      <description>&lt;P&gt;The problem is that the SA-nix and/or Splunk_TA_nix aren't being installed properly.  You might have more than 30 apps on your system and be running Splunk 6.1.   The workaround is to copy SA-nix and Splunk_TA_nix from splunk_app_for_nix/install into your $SPLUNK_HOME/etc/apps directory and restart Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160546#M14843</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2020-09-28T17:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Unix and Linux errors with configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160547#M14844</link>
      <description>&lt;P&gt;Well I didn't have more than 30 apps, but I'm on splunk 6.1. &lt;BR /&gt;
You were 100% right with your diagnosis and solution. Manually installing the two supporting apps completely fixed it!&lt;BR /&gt;
You're amazing, Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 20:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-errors-with-configuration/m-p/160547#M14844</guid>
      <dc:creator>blindauer</dc:creator>
      <dc:date>2014-07-29T20:14:09Z</dc:date>
    </item>
  </channel>
</rss>

