<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Collect SunOS-SPARC OS Logs in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742671#M29305</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263406"&gt;@dania_abujuma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to check - have you created the "os" index on your indexers?&lt;/P&gt;&lt;P&gt;Are you able to see the _internal logs for these forwarders? This will help determine if the issue is sending, or receiving the data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see any reference to these inputs (and any errors?) in the $SPLUNK_HOME/var/log/splunk/splunkd.log file?&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 09:17:22 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-03-26T09:17:22Z</dc:date>
    <item>
      <title>Collect SunOS-SPARC Logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742670#M29304</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;/P&gt;&lt;P&gt;I am looking for a way to collect the SunOS-SPARC OS logs. After some research, I have tried to update the inputs.conf in the&amp;nbsp;Splunk Add-on for Unix and Linux (&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/833" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/833&lt;/A&gt;&amp;nbsp;), as below &lt;STRONG&gt;(this is a snippet of the config file not all of it) :&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# Currently only supports SunOS, Linux, OSX.
# May require Splunk forwarder to run as root on some platforms.
[script://./bin/service.sh]
disabled = 0
interval = 3600
source = Unix:Service
sourcetype = Unix:Service
index = os

# Currently only supports SunOS, Linux, OSX.
# May require Splunk forwarder to run as root on some platforms.
[script://./bin/sshdChecker.sh]
disabled = 0
interval = 3600
source = Unix:SSHDConfig
sourcetype = Unix:SSHDConfig
index = os

# Currently only supports Linux, OSX.
# May require Splunk forwarder to run as root on some platforms.
[script://./bin/update.sh]
disabled = 0
interval = 86400
source = Unix:Update
sourcetype = Unix:Update
index = os

[script://./bin/uptime.sh]
disabled = 0
interval = 86400
source = Unix:Uptime
sourcetype = Unix:Uptime
index = os
[script://./bin/version.sh]
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;This didn't work and no logs were collected (I have made sure the user running Splunk forwarder has read privilege), is there any other recommendation?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 09:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742670#M29304</guid>
      <dc:creator>dania_abujuma</dc:creator>
      <dc:date>2025-03-26T09:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Collect SunOS-SPARC OS Logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742671#M29305</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263406"&gt;@dania_abujuma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to check - have you created the "os" index on your indexers?&lt;/P&gt;&lt;P&gt;Are you able to see the _internal logs for these forwarders? This will help determine if the issue is sending, or receiving the data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see any reference to these inputs (and any errors?) in the $SPLUNK_HOME/var/log/splunk/splunkd.log file?&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 09:17:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742671#M29305</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-26T09:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Collect SunOS-SPARC OS Logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742672#M29306</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Yes, I have created the "os" index in my indexer.&lt;/P&gt;&lt;P&gt;I can see in the _internal index logs for these hosts.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 09:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Collect-SunOS-SPARC-Logs/m-p/742672#M29306</guid>
      <dc:creator>dania_abujuma</dc:creator>
      <dc:date>2025-03-26T09:26:16Z</dc:date>
    </item>
  </channel>
</rss>

