<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Infrastructure: Error message on search head in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485265#M59664</link>
    <description>&lt;P&gt;The solution of putting the Add-On on the Search Head itself was correct.  Is that because the Search Head is basically acting like a glorified Heavy Forwarder?  A little confused as to why the Search Head is performing any parsing in this regard.  Thanks.&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2019 17:48:42 GMT</pubDate>
    <dc:creator>jbburkes</dc:creator>
    <dc:date>2019-11-15T17:48:42Z</dc:date>
    <item>
      <title>Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485257#M59656</link>
      <description>&lt;P&gt;Splunk App for Infrastructure data collection on Search Head&lt;/P&gt;

&lt;P&gt;Followed: &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/InfraApp/2.0.0/Admin/ManualInstalLinuxUF"&gt;https://docs.splunk.com/Documentation/InfraApp/2.0.0/Admin/ManualInstalLinuxUF&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Environment:&lt;BR /&gt;
Search Head 7.3.0&lt;BR /&gt;
Indexer 7.3.0&lt;/P&gt;

&lt;P&gt;Setup:&lt;BR /&gt;
collectd -&amp;gt; localhost udp port 5000 -&amp;gt; indexer (via system/local/outputs.conf)&lt;/P&gt;

&lt;P&gt;Issue:&lt;BR /&gt;
So data flows from collectd to localhost udp port 5000, verified with tcpdump to include viewing data.  Search Head forwards data to the Indexer. Indexer has Add-On as instructed in documentation but get the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Metric value = unset is not valid for source=5000 sourcetype=em_metrics_udp. Metric event data with an invalid metric value would not be indexed. Ensure the input metric data is not malformed.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 14:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485257#M59656</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2019-11-14T14:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485258#M59657</link>
      <description>&lt;P&gt;Issue:&lt;BR /&gt;
Additional Error missing from original post:&lt;/P&gt;

&lt;P&gt;Metric name is missing from source...Metric event data without metric name is invalid and would not be indexed. Ensure the input metric data is not malformed&lt;/P&gt;

&lt;P&gt;collectd.conf&lt;/P&gt;

&lt;H1&gt;Config file for collectd(1).&lt;/H1&gt;

&lt;H1&gt;Please read collectd.conf(5) for a list of options.&lt;/H1&gt;

&lt;H1&gt;&lt;A href="http://collectd.org/" target="_blank"&gt;http://collectd.org/&lt;/A&gt;&lt;/H1&gt;

&lt;H1&gt;Global&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;Global settings for the daemon.&lt;/H1&gt;

&lt;P&gt;Hostname    "XXX"&lt;BR /&gt;
FQDNLookup   false&lt;BR /&gt;
BaseDir     "/var/lib/collectd"&lt;/P&gt;

&lt;H1&gt;PIDFile     "/var/run/collectd.pid"&lt;/H1&gt;

&lt;P&gt;PluginDir   "/usr/lib64/collectd"&lt;/P&gt;

&lt;H1&gt;TypesDB     "/usr/share/collectd/types.db"&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;When enabled, plugins are loaded automatically with the default options&lt;/H1&gt;

&lt;H1&gt;when an appropriate  block is encountered.&lt;/H1&gt;

&lt;H1&gt;Disabled by default.&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;AutoLoadPlugin false&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;When enabled, internal statistics are collected, using "collectd" as the&lt;/H1&gt;

&lt;H1&gt;plugin name.&lt;/H1&gt;

&lt;H1&gt;Disabled by default.&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;CollectInternalStats false&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;Interval at which to query values. This may be overwritten on a per-plugin&lt;/H1&gt;

&lt;H1&gt;base by using the 'Interval' option of the LoadPlugin block:&lt;/H1&gt;

&lt;H1&gt;Interval 60&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;P&gt;Interval     60&lt;/P&gt;

&lt;H1&gt;MaxReadInterval 86400&lt;/H1&gt;

&lt;H1&gt;Timeout         2&lt;/H1&gt;

&lt;H1&gt;ReadThreads     5&lt;/H1&gt;

&lt;H1&gt;WriteThreads    5&lt;/H1&gt;

&lt;H1&gt;Limit the size of the write queue. Default is no limit. Setting up a limit is&lt;/H1&gt;

&lt;H1&gt;recommended for servers handling a high volume of traffic.&lt;/H1&gt;

&lt;P&gt;WriteQueueLimitHigh 1000000&lt;BR /&gt;
WriteQueueLimitLow   800000&lt;/P&gt;

&lt;H1&gt;Logging&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;Plugins which provide logging functions should be loaded first, so log&lt;/H1&gt;

&lt;H1&gt;messages generated when loading or configuring other plugins can be&lt;/H1&gt;

&lt;H1&gt;accessed.&lt;/H1&gt;

&lt;H1&gt;LoadPlugin syslog&lt;/H1&gt;

&lt;P&gt;LoadPlugin logfile&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    FlushInterval 30



server 127.0.0.1
buffersize 9000
useudp true
udpport 5000
#data_type metric
#Dimension "entity_type:linux_host"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;H1&gt;LoadPlugin section&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;Lines beginning with a single `#' belong to plugins which have been built&lt;/H1&gt;

&lt;H1&gt;but are disabled by default.&lt;/H1&gt;

&lt;H1&gt;Lines beginning with `##' belong to plugins which have not been built due&lt;/H1&gt;

&lt;H1&gt;to missing dependencies or because they have been deactivated explicitly.&lt;/H1&gt;

&lt;H1&gt;LoadPlugin csv&lt;/H1&gt;

&lt;P&gt;LoadPlugin cpu&lt;/P&gt;

&lt;H1&gt;LoadPlugin memory&lt;/H1&gt;

&lt;H1&gt;LoadPlugin df&lt;/H1&gt;

&lt;H1&gt;LoadPlugin load&lt;/H1&gt;

&lt;H1&gt;LoadPlugin disk&lt;/H1&gt;

&lt;H1&gt;LoadPlugin interface&lt;/H1&gt;

&lt;H1&gt;LoadPlugin uptime&lt;/H1&gt;

&lt;H1&gt;LoadPlugin processmon&lt;/H1&gt;

&lt;H1&gt;Plugin configuration&lt;/H1&gt;

&lt;H1&gt;----------------------------------------------------------------------------&lt;/H1&gt;

&lt;H1&gt;In this section configuration stubs for each plugin are provided. A desc-&lt;/H1&gt;

&lt;H1&gt;ription of those options is available in the collectd.conf(5) manual page.&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;LogLevel info
File "/var/log/collectd.log"
Timestamp true
PrintSeverity true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;H1&gt;LogLevel info&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;ReportByCpu false
ReportByState true
ValuesPercentage true



ValuesAbsolute false
ValuesPercentage true



FSType "ext2"
FSType "ext3"
FSType "ext4"
FSType "XFS"
FSType "rootfs"
FSType "overlay"
FSType "hfs"
FSType "apfs"
FSType "zfs"
FSType "ufs"
ReportByDevice true
ValuesAbsolute false
ValuesPercentage true
IgnoreSelected false



ReportRelative true



Disk ""
IgnoreSelected true
UdevNameAttr "DEVNAME"



IgnoreSelected true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;inputs.conf&lt;BR /&gt;
[default]&lt;BR /&gt;
host = XXX&lt;/P&gt;

&lt;P&gt;[em_entity_migration://job]&lt;BR /&gt;
disabled = 1&lt;/P&gt;

&lt;P&gt;[udp://5000]&lt;BR /&gt;
index = em_metrics&lt;BR /&gt;
sourcetype = em_metrics_udp&lt;BR /&gt;
no_appending_timestamp = true&lt;/P&gt;

&lt;P&gt;[monitor:///var/log/collectd.log]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = _internal&lt;/P&gt;

&lt;P&gt;collectd tcpdump&lt;BR /&gt;
{time: 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.user", "metric_type": "cpu", "_value": 1.41780386351553, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.system", "metric_type": "cpu", "_value": 0.293985801111308, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.wait", "metric_type": "cpu", "_value": 0.00312750852246072, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.nice", "metric_type": "cpu", "_value": 0, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.interrupt", "metric_type": "cpu", "_value": 0, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.softirq", "metric_type": "cpu", "_value": 0.00729751988574169, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.steal", "metric_type": "cpu", "_value": 0, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}{"time": 1573748903.05, "host": "XXX", "fields": {"metric_name": "cpu.idle", "metric_type": "cpu", "_value": 98.277785306965, "entity_type": "linix_host", "kernel_version": "3.10.0-1062.4.1.el7.x86_64", "os": "Red Hat Enterprise Linux Server", "os_version": "7.7 (Maipo)", "ip": "XXX"}}&lt;/P&gt;

&lt;P&gt;So my confusion is the metric name and metric value are in the event traffic, so why is the indexer throwing this error?&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:59:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485258#M59657</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2020-09-30T02:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485259#M59658</link>
      <description>&lt;P&gt;What is the version of Splunk Add on for Infrastructure on your indexers?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 18:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485259#M59658</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2019-11-14T18:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485260#M59659</link>
      <description>&lt;P&gt;Add-On and App are 2.0.0&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:01:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485260#M59659</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2019-11-14T19:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485261#M59660</link>
      <description>&lt;P&gt;We expect to use the collectd setup script, that will send data over HEC to the indexers (and skip the UF)&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;the SAI app does not use UDP&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Setup:&lt;BR /&gt;
collectd -&amp;gt; localhost udp port 5000 -&amp;gt; indexer (via system/local/outputs.conf)&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;If you send data over UDP, the format may not be recognized, as many transformations are done for the em_metrics sourcetypes.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485261#M59660</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-11-14T19:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485262#M59661</link>
      <description>&lt;P&gt;you might need TA in SH as well if you are using that to forward data instead of UF.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485262#M59661</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2019-11-14T19:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485263#M59662</link>
      <description>&lt;P&gt;we have UDP support in write_splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485263#M59662</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2019-11-14T19:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485264#M59663</link>
      <description>&lt;P&gt;So the answer was to install the Add-On on the Search Head itself, which makes me question my understanding of splunk data flow.  Is the reason the Search Head needs the Add-On installed is because it is basically acting like a HF? Thanks for your help!&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 17:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485264#M59663</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2019-11-15T17:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485265#M59664</link>
      <description>&lt;P&gt;The solution of putting the Add-On on the Search Head itself was correct.  Is that because the Search Head is basically acting like a glorified Heavy Forwarder?  A little confused as to why the Search Head is performing any parsing in this regard.  Thanks.&lt;/P&gt;

&lt;P&gt;Jeremy&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 17:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485265#M59664</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2019-11-15T17:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485266#M59665</link>
      <description>&lt;P&gt;This is the answer! Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 17:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485266#M59665</guid>
      <dc:creator>jbburkes</dc:creator>
      <dc:date>2019-11-15T17:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure: Error message on search head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485267#M59666</link>
      <description>&lt;P&gt;SII was for splunklight, it was not intended to be multi tenant, initially. SAI is an app for enterprise,  but the setup UI still assume that you have single instance (SH/IDX all in one).&lt;/P&gt;

&lt;P&gt;So when you are in an enterprise splunk deployment, read the docs :&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/InfraApp/2.0.0/Install/DistributedDeployment"&gt;https://docs.splunk.com/Documentation/InfraApp/2.0.0/Install/DistributedDeployment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You do not really want to send data to the SH , its a bottleneck, and HEC may not scale.&lt;BR /&gt;
Instead move the ingest on the indexers.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;you need to create the HEC tokens and inputs on the indexers, install the TA (with sourcetypes and indexes)&lt;/LI&gt;
&lt;LI&gt;setup a DNS loadbalancer to have a single address for all your indexers &lt;/LI&gt;
&lt;LI&gt;then customize the install script for the client to use the good token and the indexers addresses&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 15 Nov 2019 18:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-Error-message-on-search-head/m-p/485267#M59666</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-11-15T18:26:15Z</dc:date>
    </item>
  </channel>
</rss>

