<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Metrics via Splunk Add on for *nix in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446985#M15705</link>
    <description>&lt;P&gt;That would be amazing my friend. If you need help testing let me know. We have a small lab specifically for testing new versions of splunk and add ons. Keep us posted if you would be so kind. Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2018 12:52:16 GMT</pubDate>
    <dc:creator>Tohrment</dc:creator>
    <dc:date>2018-11-09T12:52:16Z</dc:date>
    <item>
      <title>Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446983#M15703</link>
      <description>&lt;P&gt;So, we aren't in an environment where we can just deploy apps (a la collectd) but want to get metrics in from Linux boxes. Has anyone figured out how to accomplish this with the Splunk Add-on for *nix? I am terrible with regex(trying to change that) so I have not been able to figure out the proper transforms to get the data in a format fit for metrics index ingestion but needing to get it into our lab for future presentations on the matter(in the hopes of getting a license bump lol). Anyway, any help would be most appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 12:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446983#M15703</guid>
      <dc:creator>Tohrment</dc:creator>
      <dc:date>2018-10-26T12:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446984#M15704</link>
      <description>&lt;P&gt;Hi, I have recently worked on a wrapper add-on to work on top of the Splunk NIX Add-On to tap in the output and convert them in to a metric event and transport it to indexers (either via Splunk TCP in csv file format, if the forwarder is of version more than 7 OR send via HTTP Event collector, if the forwarder is version less than 7). I am still trying to do some performance test around that before I can package the same as an add-on and publish it. &lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 04:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446984#M15704</guid>
      <dc:creator>fferozbasha</dc:creator>
      <dc:date>2018-11-09T04:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446985#M15705</link>
      <description>&lt;P&gt;That would be amazing my friend. If you need help testing let me know. We have a small lab specifically for testing new versions of splunk and add ons. Keep us posted if you would be so kind. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 12:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446985#M15705</guid>
      <dc:creator>Tohrment</dc:creator>
      <dc:date>2018-11-09T12:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446986#M15706</link>
      <description>&lt;P&gt;Thanks for replying, FYI 7.2 does have the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Metrics/L2MOverview"&gt;logs to metrics conversion&lt;/A&gt; but what Ferroz is describing covers older versions!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 20:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446986#M15706</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-11-09T20:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446987#M15707</link>
      <description>&lt;P&gt;I have not found anything regarding using logs to metrics to utilize the output of the Splunk Add-on for *nix. If you have a link specifically for that and not the generalized article for Logs2Metrics I would more than be happy to look over it and attempt it.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 21:01:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446987#M15707</guid>
      <dc:creator>Tohrment</dc:creator>
      <dc:date>2018-11-09T21:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446988#M15708</link>
      <description>&lt;P&gt;Nothing except the generalised article which is why this was just a comment and not an answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 21:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446988#M15708</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-11-09T21:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446989#M15709</link>
      <description>&lt;P&gt;Thanks much Tohrment. I will surely share the add-on with you for further testing. I will publish the same in splunkbase and share you the link. &lt;/P&gt;</description>
      <pubDate>Sat, 10 Nov 2018 05:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446989#M15709</guid>
      <dc:creator>fferozbasha</dc:creator>
      <dc:date>2018-11-10T05:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446990#M15710</link>
      <description>&lt;P&gt;Did you ever manage to get this setup working?  I have a need to do a logs-to-metrics for *nix TA output and any shortcuts would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 20:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446990#M15710</guid>
      <dc:creator>jherring_splunk</dc:creator>
      <dc:date>2019-08-19T20:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446991#M15711</link>
      <description>&lt;P&gt;One frustration with the Linux TA (v6.0.2) is that the output contains so much whitespace.  Ingesting that data as a metric spares your license, but you still lose on storage and speed.&lt;/P&gt;

&lt;P&gt;For example, I enabled vmstat.sh, bandwidth.sh, df.sh, and cpu.sh on one host.  Those four inputs generate 64,552 bytes / hour of raw events.  If I dedup the whitespace (replace \s+ with \s) then that shrinks to 36,465 bytes, which is 44% reduction.&lt;/P&gt;

&lt;P&gt;In other words, metrics from the Linux TA are 51% whitespace.  Anybody try to fix this?  The whitespace originates from the awk/printf commands in the bash scripts.  The commands format the output into pretty printed tables, which doesn't make sense for machine data.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446991#M15711</guid>
      <dc:creator>satyenshah</dc:creator>
      <dc:date>2019-12-11T17:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446992#M15712</link>
      <description>&lt;P&gt;Hi Tohrment,&lt;/P&gt;

&lt;P&gt;I have recently released a new add-on to collect Linux metrics without collectd &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Metrics Add-on for Infrastructure:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/4856/"&gt;https://splunkbase.splunk.com/app/4856/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;All feedback is welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;L.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 10:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/446992#M15712</guid>
      <dc:creator>lukeh</dc:creator>
      <dc:date>2020-01-30T10:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Metrics via Splunk Add on for *nix</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/507286#M17449</link>
      <description>&lt;P&gt;Hello&amp;nbsp; Lukeh,&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks&amp;nbsp; for solution&amp;nbsp;&lt;SPAN&gt;Metrics Add-on for Infrastructure.&amp;nbsp; it is&amp;nbsp; working&amp;nbsp; perfectly&amp;nbsp; for linux.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Now I am struggling&amp;nbsp; with HPUX&amp;nbsp; ,solaris and AIX.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;It would be great&amp;nbsp; if you have solution on those OS&amp;nbsp; as&amp;nbsp; well.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp; in Advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;Arijit Chowdhury&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 17:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Metrics-via-Splunk-Add-on-for-nix/m-p/507286#M17449</guid>
      <dc:creator>Arijit1</dc:creator>
      <dc:date>2020-07-03T17:57:36Z</dc:date>
    </item>
  </channel>
</rss>

