<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are Services/processes missing from ps sourcetype query? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Services-processes-missing-from-ps-sourcetype-query/m-p/592755#M103753</link>
    <description>&lt;P&gt;I have Splunk_TA_nix installed and ps.sh enabled on my Apache storm nimbus instances.&amp;nbsp; I can run a general ps sourcetype query on a service I know should always be running like rhnsd and get events back just fine ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=os host="my-stormn-1" sourcetype=ps rhnsd&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;However, when I do the same for the "stormnimbus" service I get zero events back ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=os host="my-stormn-1" sourcetype=ps stormnimbus&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meanwhile, a "sudo systemctl status stormnimbus" on the my-stormn-1 instance itself shows that it is active and running.&amp;nbsp; I'm having the same problem also with the stormui service as well as the stormsupervisor service running on my storm supervisor instances.&amp;nbsp; I should note that I do have Splunk_TA_nix installed on my splunk indexers.&amp;nbsp; Any advice as to why these services are not returning events with ps and how to fix it would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Apr 2022 20:36:52 GMT</pubDate>
    <dc:creator>bsg273</dc:creator>
    <dc:date>2022-04-06T20:36:52Z</dc:date>
    <item>
      <title>Why are Services/processes missing from ps sourcetype query?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Services-processes-missing-from-ps-sourcetype-query/m-p/592755#M103753</link>
      <description>&lt;P&gt;I have Splunk_TA_nix installed and ps.sh enabled on my Apache storm nimbus instances.&amp;nbsp; I can run a general ps sourcetype query on a service I know should always be running like rhnsd and get events back just fine ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=os host="my-stormn-1" sourcetype=ps rhnsd&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;However, when I do the same for the "stormnimbus" service I get zero events back ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=os host="my-stormn-1" sourcetype=ps stormnimbus&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meanwhile, a "sudo systemctl status stormnimbus" on the my-stormn-1 instance itself shows that it is active and running.&amp;nbsp; I'm having the same problem also with the stormui service as well as the stormsupervisor service running on my storm supervisor instances.&amp;nbsp; I should note that I do have Splunk_TA_nix installed on my splunk indexers.&amp;nbsp; Any advice as to why these services are not returning events with ps and how to fix it would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 20:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Services-processes-missing-from-ps-sourcetype-query/m-p/592755#M103753</guid>
      <dc:creator>bsg273</dc:creator>
      <dc:date>2022-04-06T20:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are Services/processes missing from ps sourcetype query?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Services-processes-missing-from-ps-sourcetype-query/m-p/592846#M103765</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243884"&gt;@bsg273&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you tried to manually debug the search?&lt;/P&gt;&lt;P&gt;in other words, running the search without the word "&lt;SPAN&gt;stormnimbus" is there a similar string?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;maybe in the ps command output it has a different value (e.g. "storm nimbus").&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You could manually search or use a part of the string (e.g. storm or nimbus) and see if the value is present in Splunk data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 07:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Services-processes-missing-from-ps-sourcetype-query/m-p/592846#M103765</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-07T07:13:12Z</dc:date>
    </item>
  </channel>
</rss>

