All Apps and Add-ons

Can't see the Unix and Linux app after installing on indexer; keep being prompted to configure in Splunk Web

Strunk
Explorer

Why can't I see the Splunk App for Unix and Linux in Splunk Web?

I installed the add-on to my deployment clients, and am trying to view the data with the app installed on my indexer. The installation appears to go okay and am prompted in Splunk Web to configure the app for the first time. However, that is all I'm able to view from the app, the configuration screen, not pretty graphs. 🙂 I've restarted my indexer several times, and I've confirmed that the universal forwarders (deployment clients) are sending data to the indexer, i.e., I can query the index ("os" in this case) directly and see data.

0 Karma
1 Solution

Strunk
Explorer

D'oh! Yes, I made the mistake; I thought I had installed the app on the indexer when I had only installed the add-on. Things are working as expected now, after installing the actual app.

View solution in original post

0 Karma

Strunk
Explorer

D'oh! Yes, I made the mistake; I thought I had installed the app on the indexer when I had only installed the add-on. Things are working as expected now, after installing the actual app.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...