<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the Splunk_TA_nix hardware sourcetype not automatically extracted? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341505#M62917</link>
    <description>&lt;P&gt;very odd, i can see extraction with an older version of the TA&lt;BR /&gt;
is your TAs permissions set to global?&lt;/P&gt;</description>
    <pubDate>Fri, 20 Apr 2018 01:04:54 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2018-04-20T01:04:54Z</dc:date>
    <item>
      <title>Why is the Splunk_TA_nix hardware sourcetype not automatically extracted?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341502#M62914</link>
      <description>&lt;P&gt;We are collecting &lt;CODE&gt;sourcetype=hardware&lt;/CODE&gt; via the Splunk_TA_nix app (v5.2.3),   but the data returned isn't being extracted.   The ./bin/hardware.sh script  is clearly written to produce tabular data,  but I seem to be missing a transform that extracts it properly.   Does that transform ship in a different app?   Am I doing something wrong?  A search-time extraction via &lt;CODE&gt;multikv&lt;/CODE&gt; isn't useful, as the $1::$2 field naming doesn't happen.&lt;/P&gt;

&lt;P&gt;In search, each event looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;KEY                   VALUE
CPU_TYPE              Intel(R) Xeon(R) CPU X5690 @ 3.47GHz
CPU_CACHE             12288 KB
CPU_COUNT             4
HARD_DRIVES           sda (Virtual disk) 200 GB;
NIC_TYPE              &amp;lt;notAvailable&amp;gt;
NIC_COUNT             1
MEMORY_REAL           16334412 kB
MEMORY_SWAP           16777208 kB
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What I want is  &lt;CODE&gt;MEMORY_REAL="16334412 kB"&lt;/CODE&gt;   etc.&lt;/P&gt;

&lt;P&gt;Splunk Enterprise 7.0.2,   Splunk_ta_nix 5.2.3,   mix of CentOS 6.7 &amp;amp; Amazon Linux&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:04:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341502#M62914</guid>
      <dc:creator>anewell</dc:creator>
      <dc:date>2020-09-29T19:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk_TA_nix hardware sourcetype not automatically extracted?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341503#M62915</link>
      <description>&lt;P&gt;did you install the TA on the Search Head?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 03:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341503#M62915</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-04-19T03:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk_TA_nix hardware sourcetype not automatically extracted?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341504#M62916</link>
      <description>&lt;P&gt;Thanks, good question.  Yes,  Splunk_TA_nix 5.2.3 installed on Seach Head Cluster as well.  &lt;/P&gt;

&lt;P&gt;I've tried searching the sourcetype directly on the indexer,  or from the main SH,  or from a different SH w/ the "Splunk App for Unix and Linux"  (&lt;A href="https://splunkbase.splunk.com/app/273/" target="_blank"&gt;https://splunkbase.splunk.com/app/273/&lt;/A&gt;) installed.  In all cases there is no extraction.   &lt;/P&gt;

&lt;P&gt;I can write the extraction transform myself, but I dislike making local changes to a splunk-provided mainstream TA.  I see there is a version 5.2.4 released; perhaps that will help. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341504#M62916</guid>
      <dc:creator>anewell</dc:creator>
      <dc:date>2020-09-29T19:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk_TA_nix hardware sourcetype not automatically extracted?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341505#M62917</link>
      <description>&lt;P&gt;very odd, i can see extraction with an older version of the TA&lt;BR /&gt;
is your TAs permissions set to global?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 01:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341505#M62917</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-04-20T01:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk_TA_nix hardware sourcetype not automatically extracted?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341506#M62918</link>
      <description>&lt;P&gt;The TA should ship with props for the [hardware] sourcetype.  I checked mine (Splunk 7.0.2 running on MacOS, Splunk_TA_nix 5.2.4), and mine includes the following extracts and evals in the default props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-RealMemory = (?i)MEMORY_REAL\s+(?P&amp;lt;RealMemory&amp;gt;[^ ]*)[ ]?
EXTRACT-SwapMemory = (?i)MEMORY_SWAP\s+(?P&amp;lt;SwapMemory&amp;gt;[^ ]*)[ ]?
EXTRACT-Unit = (?i)MEMORY_REAL\s+\d+\s+(?P&amp;lt;Unit&amp;gt;\w+)?
EVAL-RealMemoryMB = case(match(Unit, "kB"), RealMemory*pow(1024,-1), match(Unit, "KB"), RealMemory*pow(1024,-1), match(Unit, "mB"), RealMemory, match(Unit, "MB"), RealMemory, match(Unit, "gB"), RealMemory*pow(1024,1), match(Unit, "GB"), RealMemory*pow(1024,1), match(Unit, "tB"), RealMemory*pow(1024,2), match(Unit, "TB"), RealMemory*pow(1024,2), match(Unit, "pB"), RealMemory*pow(1024,3), match(Unit, "PB"), RealMemory*pow(1024,3), 1==1, "unknown")
EVAL-SwapMemoryMB = case(match(Unit, "kB"), SwapMemory*pow(1024,-1), match(Unit, "KB"), SwapMemory*pow(1024,-1), match(Unit, "mB"), SwapMemory, match(Unit, "MB"), SwapMemory, match(Unit, "gB"), SwapMemory*pow(1024,1), match(Unit, "GB"), SwapMemory*pow(1024,1), match(Unit, "tB"), SwapMemory*pow(1024,2), match(Unit, "TB"), SwapMemory*pow(1024,2), match(Unit, "pB"), SwapMemory*pow(1024,3), match(Unit, "PB"), SwapMemory*pow(1024,3), 1==1, "unknown")
EXTRACT-cpu_cores = (?i)CPU_COUNT\s+(?P&amp;lt;cpu_cores&amp;gt;[^ \n]*)?
EXTRACT-cpu_type = (?i)CPU_TYPE\s+(?P&amp;lt;cpu_type&amp;gt;[^\n]*)?
EVAL-mem = case(match(Unit, "kB"), RealMemory*pow(1024,-1), match(Unit, "KB"), RealMemory*pow(1024,-1), match(Unit, "mB"), RealMemory, match(Unit, "MB"), RealMemory, match(Unit, "gB"), RealMemory*pow(1024,1), match(Unit, "GB"), RealMemory*pow(1024,1), match(Unit, "tB"), RealMemory*pow(1024,2), match(Unit, "TB"), RealMemory*pow(1024,2), match(Unit, "pB"), RealMemory*pow(1024,3), match(Unit, "PB"), RealMemory*pow(1024,3), 1==1, "unknown")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I check the data in splunk, I have the following fields that match up to these props:  RealMemory, RealMemoryMB, SwapMemory, SwapMemoryMB, cpu_cores, cpu_type, mem&lt;/P&gt;

&lt;P&gt;If the add-on is installed on your search heads and indexers, you should get the same field extractions.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:05:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Splunk-TA-nix-hardware-sourcetype-not-automatically/m-p/341506#M62918</guid>
      <dc:creator>brian_rampley</dc:creator>
      <dc:date>2020-09-29T19:05:11Z</dc:date>
    </item>
  </channel>
</rss>

