<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk unix app not receiving inputs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91682#M19064</link>
    <description>&lt;P&gt;above answer did not solve problem, even after manually adding role OS, did not solve the issue&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2016 13:30:33 GMT</pubDate>
    <dc:creator>somchatt78</dc:creator>
    <dc:date>2016-10-21T13:30:33Z</dc:date>
    <item>
      <title>Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91676#M19058</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've enabled some of the inputs for the unix app via its configuration page.After selecting those inputs to be enabled,I've saved it but still it doesn't seem to be receiving any inputs.&lt;/P&gt;

&lt;P&gt;I've checked again at Manager&amp;gt;Data inputs&amp;gt;Scripts and those input scripts that I've selected are marked as Enabled.&lt;/P&gt;

&lt;P&gt;I've also tried restarting Splunk services but no input as well.&lt;/P&gt;

&lt;P&gt;Is there something I've missed?&lt;/P&gt;

&lt;P&gt;Fyi,splunk is installed on CentOS.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2010 09:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91676#M19058</guid>
      <dc:creator>remy06</dc:creator>
      <dc:date>2010-11-18T09:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91677#M19059</link>
      <description>&lt;P&gt;By default, the Nix app will store its data in the OS index.  &lt;/P&gt;

&lt;P&gt;You may need to add "index=os" to the beginning of your search as well.  &lt;/P&gt;

&lt;P&gt;You could also add &lt;EM&gt;OS&lt;/EM&gt; to the list of &lt;EM&gt;selected roles&lt;/EM&gt; via the Manager -&amp;gt; Access controls -&amp;gt; Roles.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2010 12:01:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91677#M19059</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2010-11-18T12:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91678#M19060</link>
      <description>&lt;P&gt;When I do a search for index=os,nothing shows up.&lt;BR /&gt;
When I'm at the Over&amp;gt;About Splunk for Unix page, there is still no Hosts,Sourcetypes and Sources listed.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2010 14:22:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91678#M19060</guid>
      <dc:creator>remy06</dc:creator>
      <dc:date>2010-11-18T14:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91679#M19061</link>
      <description>&lt;P&gt;I've did a check on splunkd logs and found number of errors like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;11-24-2010 10:33:37.162 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/unix/bin/top.sh" /bin/sh: /opt/splunk/etc/apps/unix/bin/top.sh: /bin/sh^M: bad interpreter: No such file or directory&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;They do exist..&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2010 10:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91679#M19061</guid>
      <dc:creator>remy06</dc:creator>
      <dc:date>2010-11-24T10:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91680#M19062</link>
      <description>&lt;P&gt;Any idea on this??&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2010 10:09:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91680#M19062</guid>
      <dc:creator>remy06</dc:creator>
      <dc:date>2010-12-02T10:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91681#M19063</link>
      <description>&lt;P&gt;From your log output, you show "/bin/sh^M".  Did you copy the files from another non unix host?  It looks like you may have a dos-&amp;gt;unix file translation issue. Go to /opt/splunk/etc/apps/unix and "dos2unix top.sh" and see if that clears that error message.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2010 00:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91681#M19063</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2010-12-09T00:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unix app not receiving inputs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91682#M19064</link>
      <description>&lt;P&gt;above answer did not solve problem, even after manually adding role OS, did not solve the issue&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 13:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-unix-app-not-receiving-inputs/m-p/91682#M19064</guid>
      <dc:creator>somchatt78</dc:creator>
      <dc:date>2016-10-21T13:30:33Z</dc:date>
    </item>
  </channel>
</rss>

