<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAI, why no metrics from Linux with collectd write_splunk plugin? But it seems HEC is receiving data. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485131#M62052</link>
    <description>&lt;P&gt;Solved, previously I select collectd_htttp as sourcetype, and it seems the em_metrics sourcetype is mandatory for collectd write_splunk plugin, change to em_metrics then solved.&lt;BR /&gt;
em_metrics index is also mandatory for SAI, use other index then you have to adjust macros of SAI.&lt;/P&gt;

&lt;P&gt;So, use em_metrics for both sourcetype and index.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:27:06 GMT</pubDate>
    <dc:creator>yhu_splunk</dc:creator>
    <dc:date>2020-09-30T04:27:06Z</dc:date>
    <item>
      <title>SAI, why no metrics from Linux with collectd write_splunk plugin? But it seems HEC is receiving data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485130#M62051</link>
      <description>&lt;P&gt;I have Splunk App for Infrastructure installed and configured, it works for Windows agent, but I cannot make it for Linux server.&lt;/P&gt;

&lt;P&gt;Collectd seems runs well with write_splunk plugin, I run search &lt;BR /&gt;
      index="_introspection" token| spath "data.token_name" | search "data.token_name"="collectd token"&lt;BR /&gt;
looks the HEC is receiving data like the screenshot shows.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/284634-screen-shot-2020-03-03-at-21745-pm.png" alt="alt text" /&gt;&lt;BR /&gt;
But there is no data of the metrics index assigned to the HEC token, and search for &lt;BR /&gt;
     | mstats count WHERE index=* AND metric_name=* by host, metric_name&lt;BR /&gt;
only Windows host shows. &lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/284636-screen-shot-2020-03-03-at-23057-pm.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485130#M62051</guid>
      <dc:creator>yhu_splunk</dc:creator>
      <dc:date>2020-09-30T04:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: SAI, why no metrics from Linux with collectd write_splunk plugin? But it seems HEC is receiving data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485131#M62052</link>
      <description>&lt;P&gt;Solved, previously I select collectd_htttp as sourcetype, and it seems the em_metrics sourcetype is mandatory for collectd write_splunk plugin, change to em_metrics then solved.&lt;BR /&gt;
em_metrics index is also mandatory for SAI, use other index then you have to adjust macros of SAI.&lt;/P&gt;

&lt;P&gt;So, use em_metrics for both sourcetype and index.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485131#M62052</guid>
      <dc:creator>yhu_splunk</dc:creator>
      <dc:date>2020-09-30T04:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: SAI, why no metrics from Linux with collectd write_splunk plugin? But it seems HEC is receiving data.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485132#M62053</link>
      <description>&lt;P&gt;OMG!  I spent at least a day (off and on) trying to figure this out.&lt;BR /&gt;
UGH.&lt;BR /&gt;
Thank you so much!!!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 20:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SAI-why-no-metrics-from-Linux-with-collectd-write-splunk-plugin/m-p/485132#M62053</guid>
      <dc:creator>jasonstone</dc:creator>
      <dc:date>2020-05-01T20:06:28Z</dc:date>
    </item>
  </channel>
</rss>

