<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to index Nix metrics via Splunk Add-on for Splunk Nix instances? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-Nix-metrics-via-Splunk-Add-on-for-Splunk-Nix/m-p/523000#M18013</link>
    <description>&lt;P&gt;I want to monitor our Linux Splunk instances and am using the Splunk Add-on for Nix to collect metrics data and am sending it to em_metrics index and monitoring them as SAI entities via SAI on search head.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;We have a clustered environment. I am trying to get data from 3 members indexer cluster and 3 members SH cluster. We have universal forwarders installed on all of our instances. I tried to deploy the add-on to UF’s but I couldn’t see the entities on SAI (no data coming through from the hosts).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I have installed Nix add-on to the indexer cluster and SH cluster and have changed the inputs to send data to em_metrics index being used in SAI.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue that I am facing is for the indexer/SH cluster it is only displaying indexer master and SH cluster captain entities in SAI. I can see the IP's of other members in the dimensions of entities, but I want each host as a seperate entity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could anyone please guide me through if I am doing something wrong or how I can achieve what I want to see SAI app? I have been stuck for a few days, so any help is appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Oct 2020 19:47:03 GMT</pubDate>
    <dc:creator>Abha11</dc:creator>
    <dc:date>2020-10-06T19:47:03Z</dc:date>
    <item>
      <title>How to index Nix metrics via Splunk Add-on for Splunk Nix instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-Nix-metrics-via-Splunk-Add-on-for-Splunk-Nix/m-p/523000#M18013</link>
      <description>&lt;P&gt;I want to monitor our Linux Splunk instances and am using the Splunk Add-on for Nix to collect metrics data and am sending it to em_metrics index and monitoring them as SAI entities via SAI on search head.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;We have a clustered environment. I am trying to get data from 3 members indexer cluster and 3 members SH cluster. We have universal forwarders installed on all of our instances. I tried to deploy the add-on to UF’s but I couldn’t see the entities on SAI (no data coming through from the hosts).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I have installed Nix add-on to the indexer cluster and SH cluster and have changed the inputs to send data to em_metrics index being used in SAI.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue that I am facing is for the indexer/SH cluster it is only displaying indexer master and SH cluster captain entities in SAI. I can see the IP's of other members in the dimensions of entities, but I want each host as a seperate entity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could anyone please guide me through if I am doing something wrong or how I can achieve what I want to see SAI app? I have been stuck for a few days, so any help is appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 19:47:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-index-Nix-metrics-via-Splunk-Add-on-for-Splunk-Nix/m-p/523000#M18013</guid>
      <dc:creator>Abha11</dc:creator>
      <dc:date>2020-10-06T19:47:03Z</dc:date>
    </item>
  </channel>
</rss>

