<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use collectd on a remote host with Universal Forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614453#M106322</link>
    <description>&lt;P&gt;&amp;nbsp;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/173847"&gt;@eholz1&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;There are a few examples you can use to assist getting collectd metrics into Splunk via hec&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The Splunk Addon for Linux docs describe how to send collectd via HEC&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The Analytics for Linux app also has working examples.&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/3777/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/3777/#/details&lt;/A&gt;&lt;/P&gt;&lt;P&gt;They both use the write_http plugin in collectd.conf&lt;/P&gt;&lt;P&gt;Read the docs page to ensure you are setting the HEC up correctly.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/UsetheHTTPEventCollector" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Sep 2022 10:28:58 GMT</pubDate>
    <dc:creator>chaker</dc:creator>
    <dc:date>2022-09-25T10:28:58Z</dc:date>
    <item>
      <title>How to use collectd on a remote host with Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614398#M106317</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;My goals is to send rrd file data to a splunk indexer.&lt;/P&gt;
&lt;P&gt;I have a remote host that currently forwards linux_secure data to the indexer - works fie.&lt;/P&gt;
&lt;P&gt;I am NEVER able to create an input for any port tcp or otherwise from this dialog window:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eholz1_0-1663970876641.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21648i8EFE6A3762A889EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eholz1_0-1663970876641.png" alt="eholz1_0-1663970876641.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I configure a TCP forward-server using lthe UF the forward-server never goes active - I only get "cooked" data on the indexer. the host and source type are configured&lt;/P&gt;
&lt;P&gt;If I configure a port (tcp or udp) from here: this comes from Data/Data inputs/TCP&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eholz1_1-1663971021604.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21649i41DB8333D30108E0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eholz1_1-1663971021604.png" alt="eholz1_1-1663971021604.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This setting comes from Settings/Data/Forwarding and receiving&lt;/P&gt;
&lt;P&gt;I get data to the indexer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I may be missing something.&lt;/P&gt;
&lt;P&gt;I installed collectd on a remote host, configured it for the csv plug in, and the cpu plugin -&amp;nbsp; this data is being collected and save to the /var/lib/collectd directory on the remote host.&lt;/P&gt;
&lt;P&gt;How can I get this data to splunk and graph it?&lt;/P&gt;
&lt;P&gt;I can see data coming in - but cannot do anything with it. The splunk web site says that the HEC inputs must be used to get metrics into splunk. How do I configure the remote host to do this? I.E. send the data from collectd to splunk,&lt;/P&gt;
&lt;P&gt;I am open to suggestions and clarification&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;eholz1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Sep 2022 03:40:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614398#M106317</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2022-09-24T03:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to use collectd on a remote host with Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614453#M106322</link>
      <description>&lt;P&gt;&amp;nbsp;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/173847"&gt;@eholz1&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;There are a few examples you can use to assist getting collectd metrics into Splunk via hec&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The Splunk Addon for Linux docs describe how to send collectd via HEC&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The Analytics for Linux app also has working examples.&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/3777/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/3777/#/details&lt;/A&gt;&lt;/P&gt;&lt;P&gt;They both use the write_http plugin in collectd.conf&lt;/P&gt;&lt;P&gt;Read the docs page to ensure you are setting the HEC up correctly.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/UsetheHTTPEventCollector" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 10:28:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614453#M106322</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2022-09-25T10:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to use collectd on a remote host with Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614575#M106345</link>
      <description>&lt;P&gt;Hello Chaker,&lt;/P&gt;&lt;P&gt;Thanks for responding to my question. I will review the links you placed in your respose.&lt;/P&gt;&lt;P&gt;This will help.&lt;/P&gt;&lt;P&gt;Thank you very much for taking the time to respond.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eholz1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 14:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614575#M106345</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2022-09-26T14:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to use collectd on a remote host with Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614576#M106346</link>
      <description>&lt;P&gt;Forgot to ask,&lt;/P&gt;&lt;P&gt;I have collectd installed on the remote host, not the indexer. Should collectd be installed on the indexer and point to the remote host I want to monitor?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;eholz1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 14:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-collectd-on-a-remote-host-with-Universal-Forwarder/m-p/614576#M106346</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2022-09-26T14:28:15Z</dc:date>
    </item>
  </channel>
</rss>

