<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App/Add-on for Unix and Linux not collecting data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211322#M22706</link>
    <description>&lt;P&gt;I was not aware I had to install the add-on on the Indexer as well. Issue resolved.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2017 22:06:13 GMT</pubDate>
    <dc:creator>bayman</dc:creator>
    <dc:date>2017-01-03T22:06:13Z</dc:date>
    <item>
      <title>Splunk App/Add-on for Unix and Linux not collecting data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211320#M22704</link>
      <description>&lt;P&gt;Splunk Enterprise 6.5.1 installed for Indexer/Search head single instance server&lt;BR /&gt;
Splunk Add-on for Unix and Linux 5.2.3 installed on a remote Linux server w/ UniversalForwarder installed&lt;BR /&gt;
Splunk App for Unix and Linux 5.2.2 installed on Indexer/Search head&lt;/P&gt;

&lt;P&gt;When i restart the universalforwarder after installing the Add-on on the remote linux server, I do not see an os index created on the indexer as suggested by the documentation.&lt;/P&gt;

&lt;P&gt;I also copied the $SPLUNK_HOME/etc/apps/Splunk_TA_nix/default/inputs.conf to $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local/inputs.conf and enabled a few stanzas.&lt;/P&gt;

&lt;P&gt;When I open the App from Splunk web, it just shows "Waiting for results.." and I don't see any data or even the host.   &lt;/P&gt;

&lt;P&gt;I am also getting the message: "Received event for unconfigured/disabled/deleted index=os with source="source::cpu" host="host::limelight" sourcetype="sourcetype::cpu". So far received events from 1 missing index(es)."  &lt;/P&gt;

&lt;P&gt;Do I need to manually create index=os somewhere?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:14:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211320#M22704</guid>
      <dc:creator>bayman</dc:creator>
      <dc:date>2020-09-29T12:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App/Add-on for Unix and Linux not collecting data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211321#M22705</link>
      <description>&lt;P&gt;Index has to be created on the Indexer/Search head. If you have installed the app/add-on on the indexer, you have to restart the indexer also to reflect the app.&lt;/P&gt;

&lt;P&gt;Please check the following.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is there an indexes.conf inside the /apps/Splunk_TA_nix/default and contain stanza with &lt;STRONG&gt;[os]&lt;/STRONG&gt; ?&lt;/LI&gt;
&lt;LI&gt;Have you restarted the indexer after installing this add-on ?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211321#M22705</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-09-29T12:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App/Add-on for Unix and Linux not collecting data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211322#M22706</link>
      <description>&lt;P&gt;I was not aware I had to install the add-on on the Indexer as well. Issue resolved.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2017 22:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-Add-on-for-Unix-and-Linux-not-collecting-data/m-p/211322#M22706</guid>
      <dc:creator>bayman</dc:creator>
      <dc:date>2017-01-03T22:06:13Z</dc:date>
    </item>
  </channel>
</rss>

