All Apps and Add-ons

How to troubleshoot why the Splunk App for Unix and Linux shows hosts and groups, but is not showing any data?

sidhantbhayana
Path Finder

Hi All,

I have the Splunk App for Unix and Linux installed and configured as mentioned in the docs, but could not receive or index data. Any help is appreciated.

Thanks,
SB

0 Karma
1 Solution

sidhantbhayana
Path Finder

Issue is resolved now, had to create a new index on indexer, all other configurations worked well. Thanks a lot for all your inputs guys.

View solution in original post

0 Karma

sidhantbhayana
Path Finder

Issue is resolved now, had to create a new index on indexer, all other configurations worked well. Thanks a lot for all your inputs guys.

0 Karma

ryanoconnor
Builder

Can you explain your setup a little bit? Did you install this app on a Universal Forwarder and are trying to send data to Splunk Enterprise?

Can you post your local inputs.conf file so we can see what you are collecting?

Are you recieving any data from the host that the Splunk app for *nix is installed on? You can verify this by looking for that host in the _internal index

0 Karma

sjalexander
Path Finder

@ryanoconnor is on point with his request re: the inputs.conf - note that everything in there is disabled by default.

0 Karma

sjalexander
Path Finder

Hard to say anything about this without more detail - but you might be able to find your problem in the splunk log on the forwarder. have a look at the logs in /opt/splunkforwarder/var/log/splunk/ for relevant information about what the forwarder is doing/not doing. Most relevant is probably splunkd-utility.log, and possibly splunkd.log, in that directory.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...