<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Entities not displayed in Splunk App for Infrastructure. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479795#M58967</link>
    <description>&lt;P&gt;In the UF logs on &lt;STRONG&gt;Machine 2&lt;/STRONG&gt; getting the message that it's connected to &lt;STRONG&gt;Machine 1&lt;/STRONG&gt; but when I visited in &lt;STRONG&gt;Forwarder Management&lt;/STRONG&gt; tab then it's not displayed there.&lt;/P&gt;

&lt;P&gt;For the reference please refer the last few lines of UF logs after starting UF:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;01-07-2020 05:35:13.024 -0500 INFO  TcpOutputProc - Connected to idx=192.168.1.15:9997, pset=0, reuse=0.&lt;BR /&gt;
01-07-2020 05:35:13.029 -0500 INFO  WatchedFile - Will begin reading at offset=13776943 for file='/data/splunkforwarder/var/log/splunk/metrics.log'.&lt;BR /&gt;
01-07-2020 05:35:13.032 -0500 INFO  WatchedFile - Will begin reading at offset=978 for file='/data/splunkforwarder/var/log/splunk/conf.log'.&lt;BR /&gt;
01-07-2020 05:35:42.667 -0500 INFO  ScheduledViewsReaper - Scheduled views reaper run complete. Reaped count=0 scheduled views&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2020 11:03:58 GMT</pubDate>
    <dc:creator>himanshutejwani</dc:creator>
    <dc:date>2020-01-07T11:03:58Z</dc:date>
    <item>
      <title>Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479791#M58963</link>
      <description>&lt;P&gt;I have set up a Universal Forwarder(UF) from the script on &lt;STRONG&gt;Machine 2&lt;/STRONG&gt; but UF is not added on Splunk Enterprise(&lt;STRONG&gt;Machine 1&lt;/STRONG&gt;).&lt;BR /&gt;
I have manually added the deployment server and in this case, the UF is added on Splunk Enterprise but the entity is not displayed on Splunk App for Infrastructure for which I have waited for more than 5 mins.&lt;/P&gt;

&lt;P&gt;Followed the below link to install SAI on Splunk Enterprise:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/InfraApp/2.0.1/Install/Install"&gt;https://docs.splunk.com/Documentation/InfraApp/2.0.1/Install/Install&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 12:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479791#M58963</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-06T12:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479792#M58964</link>
      <description>&lt;P&gt;Does the splunkd.log from the UF say anything about whether the data is successfully sending to Machine 1?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 22:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479792#M58964</guid>
      <dc:creator>pwu_splunk</dc:creator>
      <dc:date>2020-01-06T22:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479793#M58965</link>
      <description>&lt;P&gt;Can you clarify your setup more:&lt;/P&gt;

&lt;P&gt;Machine 2 is running SAI(Splunk app for infrastructure) and SAI Add-on?&lt;BR /&gt;
Did you use script on "Add Data" page of the app? Are you trying to monitor Machine 1? Is it Windows or Linux?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 22:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479793#M58965</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-01-06T22:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479794#M58966</link>
      <description>&lt;P&gt;My both machines are Linux, SAI is installed on &lt;STRONG&gt;Machine 1(Server Machine)&lt;/STRONG&gt;  with SAI Add-on and now I am trying to install UF on &lt;STRONG&gt;Machine 2(Client Machine)&lt;/STRONG&gt; with the help of script from "Add Data" page of the App. So, I am trying to monitor &lt;STRONG&gt;Machine 2&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 07:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479794#M58966</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-07T07:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479795#M58967</link>
      <description>&lt;P&gt;In the UF logs on &lt;STRONG&gt;Machine 2&lt;/STRONG&gt; getting the message that it's connected to &lt;STRONG&gt;Machine 1&lt;/STRONG&gt; but when I visited in &lt;STRONG&gt;Forwarder Management&lt;/STRONG&gt; tab then it's not displayed there.&lt;/P&gt;

&lt;P&gt;For the reference please refer the last few lines of UF logs after starting UF:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;01-07-2020 05:35:13.024 -0500 INFO  TcpOutputProc - Connected to idx=192.168.1.15:9997, pset=0, reuse=0.&lt;BR /&gt;
01-07-2020 05:35:13.029 -0500 INFO  WatchedFile - Will begin reading at offset=13776943 for file='/data/splunkforwarder/var/log/splunk/metrics.log'.&lt;BR /&gt;
01-07-2020 05:35:13.032 -0500 INFO  WatchedFile - Will begin reading at offset=978 for file='/data/splunkforwarder/var/log/splunk/conf.log'.&lt;BR /&gt;
01-07-2020 05:35:42.667 -0500 INFO  ScheduledViewsReaper - Scheduled views reaper run complete. Reaped count=0 scheduled views&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 11:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479795#M58967</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-07T11:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479796#M58968</link>
      <description>&lt;P&gt;"Add Data" script installs both collectd(Metrics) and UF(logs) for Linux machine.&lt;BR /&gt;
Also check, "/etc/collectd/collectd.logs" for any errors.&lt;BR /&gt;
For machine 2, what is you Linux distro like Centos, Ubuntu? and what version?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 17:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479796#M58968</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-01-07T17:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479797#M58969</link>
      <description>&lt;P&gt;Is the data arriving at Machine 1? If you search &lt;CODE&gt;index=_internal host=${Machine 2}&lt;/CODE&gt; or &lt;CODE&gt;| mcatalog values(metric_name) WHERE host=${Machine 2} AND index=em_metrics&lt;/CODE&gt;, do you see data?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 18:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479797#M58969</guid>
      <dc:creator>pwu_splunk</dc:creator>
      <dc:date>2020-01-07T18:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479798#M58970</link>
      <description>&lt;P&gt;Yes, Gettings logs at &lt;STRONG&gt;Machine 1&lt;/STRONG&gt; but didn't get the metrics.&lt;/P&gt;

&lt;P&gt;I am getting the output of this command:&lt;BR /&gt;
&lt;STRONG&gt;index=_internal host=${Machine 2}&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;but didn't get any output of this command:&lt;BR /&gt;
&lt;STRONG&gt;| mcatalog values(metric_name) WHERE host=${Machine 2} AND index=em_metrics&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:36:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479798#M58970</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-09-30T03:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479799#M58971</link>
      <description>&lt;P&gt;For both Machine 1 and Machine 2 I am using &lt;STRONG&gt;Ubuntu 18.04 LTS&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;This file doesn't exist on Machine 2(client machine): &lt;STRONG&gt;/etc/collectd/collectd.logs&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 14:42:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479799#M58971</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-08T14:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479800#M58972</link>
      <description>&lt;P&gt;Check if collectd running or installed on monitored Machine 2..&lt;/P&gt;

&lt;P&gt;apt-cache policy collectd&lt;BR /&gt;
ps -ef | grep collectd&lt;/P&gt;

&lt;P&gt;Did you get any errors when you ran the script from "Add Data" page?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 18:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479800#M58972</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-01-08T18:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479801#M58973</link>
      <description>&lt;P&gt;The specific location of the collectd.log may vary by distro, but the information should be in the collectd.log on Machine 2.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 00:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479801#M58973</guid>
      <dc:creator>pwu_splunk</dc:creator>
      <dc:date>2020-01-09T00:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479802#M58974</link>
      <description>&lt;P&gt;I have reinstalled it from the script and get the below error in the &lt;STRONG&gt;collectd.logs&lt;/STRONG&gt;:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;[2020-01-09 08:31:40] [error] processmon plugin: Error reading /proc/12820/stat&lt;BR /&gt;
[2020-01-09 08:31:40] [notice] read-function of plugin `processmon' failed. Will suspend it for 120.000 seconds.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 08:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479802#M58974</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-09T08:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479803#M58975</link>
      <description>&lt;P&gt;Yes, collectd is installed and running, verified from the above 2 commands.&lt;/P&gt;

&lt;P&gt;Yes, getting error in the &lt;STRONG&gt;collectd.logs&lt;/STRONG&gt;:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;[2020-01-09 08:31:40] [error] processmon plugin: Error reading /proc/12820/stat&lt;BR /&gt;
[2020-01-09 08:31:40] [notice] read-function of plugin `processmon' failed. Will suspend it for 120.000 seconds.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 09:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479803#M58975</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-09T09:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479804#M58976</link>
      <description>&lt;P&gt;Ignore that error. It's just that process died while it was being monitored.&lt;/P&gt;

&lt;P&gt;To debug, let's try some steps:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Machine2: Do you see any recurring errors like "curl_easy_perform failed" in collectd.log ?&lt;/LI&gt;
&lt;LI&gt;In Machine 1, Check if all the Hec tokens are enabled: Settings -&amp;gt; Data Inputs -&amp;gt;HTTP Event Collector&lt;/LI&gt;
&lt;LI&gt;Machine 1: Check the Global Settings on the same page as 2. Verify "enable ssl" is checked and note down the port number.&lt;/LI&gt;
&lt;LI&gt;Machine 1: Verify the HEC token you are using has default index as "em_metrics"&lt;/LI&gt;
&lt;LI&gt;Now In Machine 2, check /etc/collectd/collectd.conf file. Verify that HEC token, server and port number in write_splunk stanza is correct.&lt;/LI&gt;
&lt;LI&gt;If still not solved, try sending fake data from Machine 2 to Machine 1 using curl and see if you get success. Here is the curl command you need to run in Machine 2:
curl -k &lt;A href="https://Machine1:8088/services/collector" target="_blank"&gt;https://Machine1:8088/services/collector&lt;/A&gt; -H "Authorization: Splunk hec_token_here" -d '{"time": 1486683865.000,"event":"metric","source":"disk","host":"host_99","fields":{"region":"us-west-1","datacenter":"us-west-1a","rack":"63","os":"Ubuntu16.10","arch":"x64","team":"LON","service":"6","service_version":"0","service_environment":"test","path":"/dev/sda1","fstype":"ext3","_value":1099511627776,"metric_name":"total"}}'&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.3/Metrics/GetMetricsInOther#Example_of_sending_metrics_using_HEC" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.3/Metrics/GetMetricsInOther#Example_of_sending_metrics_using_HEC&lt;/A&gt;&lt;BR /&gt;
&lt;STRONG&gt;&lt;EM&gt;Update token, port and server in the command&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479804#M58976</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-09-30T03:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479805#M58977</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Got the below error in the &lt;STRONG&gt;collectd.logs&lt;/STRONG&gt; when searched for "curl_easy_perform failed":&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;EM&gt;[error] write splunk plugin: curl_easy_perform failed to connect to 192.168.1.15:8088 with status 7: Couldn't connect to server&lt;/EM&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Yes, I have already enabled all the HEC tokens.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In the Global Settings, SSL is already enabled and the port number is 8088(default).&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;HEC token which I am using has default index as "em_metrics".&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;HEC token, Server IP and port number in &lt;STRONG&gt;/etc/collectd/collectd.conf&lt;/STRONG&gt; file is correct.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Getting the below output of the given curl command:&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;EM&gt;{"text":"Server is busy","code":9,"invalid-event-number":0}&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479805#M58977</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-09-30T03:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479806#M58978</link>
      <description>&lt;P&gt;Try this:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/453888/after-configuring-the-http-event-collector-why-am.html"&gt;https://answers.splunk.com/answers/453888/after-configuring-the-http-event-collector-why-am.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 13:55:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479806#M58978</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-01-10T13:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479807#M58979</link>
      <description>&lt;P&gt;Yeah, it's working now, I have &lt;STRONG&gt;unchecked&lt;/STRONG&gt; the &lt;STRONG&gt;Use Deployment Server&lt;/STRONG&gt; option from Global Settings.&lt;BR /&gt;
Thanks, dagarwal&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 07:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479807#M58979</guid>
      <dc:creator>himanshutejwani</dc:creator>
      <dc:date>2020-01-13T07:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479808#M58980</link>
      <description>&lt;P&gt;To conclude the steps for resolving Metrics data (collectd) collection issues:&lt;BR /&gt;
(NOTE: machine2 is the monitored Linux machine i.e running collectd and Splunk UF; machine 1 is running SAI And SAI Add-on)&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Check if collectd running or installed on monitored Machine 2..&lt;BR /&gt;
apt-cache policy collectd&lt;BR /&gt;
ps -ef | grep collectd&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Check Metrics data coming in: | mcatalog values(metric_name) WHERE host=${Machine 2} AND index=em_metrics&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Machine2: Do you see any recurring errors like "curl_easy_perform failed" in collectd.log or any other error?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In Machine 1, Check if all the Hec tokens are enabled: Settings -&amp;gt; Data Inputs -&amp;gt;HTTP Event Collector&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Machine 1: Check the Global Settings on the same page as 2. Verify "enable ssl" is checked, "Use Deployment Server" unchecked and note down the port number.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Machine 1: Verify the HEC token you are using has default index as "em_metrics"&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Now In Machine 2, check /etc/collectd/collectd.conf file. Verify that HEC token, server and port number in write_splunk stanza is correct.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Try sending fake data from Machine 2 to Machine 1 using curl and see if you get success. Here is the curl command you need to run in Machine 2:&lt;BR /&gt;
curl -k &lt;A href="https://Machine1:8088/services/collector" target="_blank"&gt;https://Machine1:8088/services/collector&lt;/A&gt; -H "Authorization: Splunk hec_token_here" -d '{"time": 1486683865.000,"event":"metric","source":"disk","host":"host_99","fields":{"region":"us-west-1","datacenter":"us-west-1a","rack":"63","os":"Ubuntu16.10","arch":"x64","team":"LON","service":"6","service_version":"0","service_environment":"test","path":"/dev/sda1","fstype":"ext3","_value":1099511627776,"metric_name":"total"}}'&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You should see "Success" Message. If not, try to fix the error message that you get. &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.3/Metrics/GetMetricsInOther#Example_of_sending_metrics_using_HEC" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.3/Metrics/GetMetricsInOther#Example_of_sending_metrics_using_HEC&lt;/A&gt;&lt;BR /&gt;
Update token, port and server in the command&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479808#M58980</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-09-30T03:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479809#M58981</link>
      <description>&lt;P&gt;I have followed the above steps and I can able to test fake data and getting success message. However still I am not able to see Machine 2 in Entities.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 03:50:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479809#M58981</guid>
      <dc:creator>3es</dc:creator>
      <dc:date>2020-03-16T03:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Entities not displayed in Splunk App for Infrastructure.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479810#M58982</link>
      <description>&lt;P&gt;What are the search results for Step 2?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 16:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Entities-not-displayed-in-Splunk-App-for-Infrastructure/m-p/479810#M58982</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-03-16T16:47:18Z</dc:date>
    </item>
  </channel>
</rss>

