All Apps and Add-ons

How to install *Nix app

djfisher
Explorer

Hi gang,
I have been trying to install the newer Splunk App for Unix and Linux (5.0.0) on my Splunk recievers. I tried "upgrading" the Nix 4.6 and also tried to install it by itself. The download file from Splunk is a zip file, I was expecting a .tgz file. When I try to install or upgrade from the Splunk GUI, it just gives me a /etc ? app. This directory called etc does get loaded under /opt/splunk/etc/apps. I am not sure how to get this to work. I have NIX 4.6 working fine and have the Splunk_TA_nix running fine on my forwarders.

I am running Splunk 6.0 on my receivers and forwarders.

0 Karma
1 Solution

cramasta
Builder

You need to extract the contents of the zip. You cant install it directly or you will see the /etc app listed.

The instructions are listed here

http://docs.splunk.com/Documentation/UnixApp/5.0/User/InstalltheSplunkAppforUnixandLinux

View solution in original post

ww9rivers
Contributor

I have had the same problem.

Turns out: The Splunk for *NIX app version 5.0.0 is broken.

The fix is to install version 5.0.1 -- You may have to manually delete the "...etc/apps/etc" folder.

I realize this is an old posting, but still want to point out the problem with 5.0.0.

0 Karma

cramasta
Builder

You need to extract the contents of the zip. You cant install it directly or you will see the /etc app listed.

The instructions are listed here

http://docs.splunk.com/Documentation/UnixApp/5.0/User/InstalltheSplunkAppforUnixandLinux

Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...