All Apps and Add-ons

How can we collect linux performance metrics on a windows splunk instance ?

mahajanamit
Explorer

In our infrastructure, we have our splunk indexer running on a windows machine. We are already collecting performance metrics from remote Windows machines, but we also want to collect the system, CPU and memory counters of a linux machine on the same indexer.
How can i achieve that ?

(I have installed Splunk App for Unix and Linux on my local system and running linux on a vmware but I don't see any options on this app which can enable me to connect to the linux system.)

0 Karma
1 Solution

kml_uvce
Builder

you need to install "splunk addon unix and linux" add-on in forwarder in your linux system

https://apps.splunk.com/app/833/

kamal singh bisht

View solution in original post

0 Karma

kml_uvce
Builder

you need to install "splunk addon unix and linux" add-on in forwarder in your linux system

https://apps.splunk.com/app/833/

kamal singh bisht
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The indexer doesn't connect to the remote linux system to collect the data, there's no WMI or similar.

Instead, you install a Splunk Universal Forwarder along with the linux addon linked above on the remote machine and the linux app on your indexer. The forwarder collects the data locally and sends it to your indexer to be searched and displayed there.

0 Karma

mahajanamit
Explorer

Hi

Can you please elaborate a bit more. By forwarder do you mean a universal forwarder or a splunk indexer which would work as a forwarder from the linux machine ?

0 Karma

kml_uvce
Builder

install forwarder in your linux machine and also install add on (link given) in linux machine. you need to enable scripts in this add on if disabled (check disabled option in inputs.conf in add on) , configure forwarder to send data to indexer, and these scripts fetch performance metrics and send data to indexer.

kamal singh bisht
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...