All Apps and Add-ons

Can't see the Unix and Linux app after installing on indexer; keep being prompted to configure in Splunk Web

Strunk
Explorer

Why can't I see the Splunk App for Unix and Linux in Splunk Web?

I installed the add-on to my deployment clients, and am trying to view the data with the app installed on my indexer. The installation appears to go okay and am prompted in Splunk Web to configure the app for the first time. However, that is all I'm able to view from the app, the configuration screen, not pretty graphs. 🙂 I've restarted my indexer several times, and I've confirmed that the universal forwarders (deployment clients) are sending data to the indexer, i.e., I can query the index ("os" in this case) directly and see data.

0 Karma
1 Solution

Strunk
Explorer

D'oh! Yes, I made the mistake; I thought I had installed the app on the indexer when I had only installed the add-on. Things are working as expected now, after installing the actual app.

View solution in original post

0 Karma

Strunk
Explorer

D'oh! Yes, I made the mistake; I thought I had installed the app on the indexer when I had only installed the add-on. Things are working as expected now, after installing the actual app.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...