All Apps and Add-ons

Index iostat data using nix

camah4
New Member

Hi,

We collect sar/iostat data on our servers which are written to files. I would like to view the data collected in splunk using nix. At the moment we rsync the files from our production system to our internal systems for monitoring. I would like to have our internal splunk system index this data and view it using nix. Is this possible given our current configuration.

Thanks

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

Sure, you will just need to have Splunk index the sar/iostat output files with the same sourcetype as the unix app is expecting (e.g. sourcetype=sar, sourcetype=iostat). You will also need to ensure that field extractions are consistent between the default unix extractions and your data.

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

Sure, you will just need to have Splunk index the sar/iostat output files with the same sourcetype as the unix app is expecting (e.g. sourcetype=sar, sourcetype=iostat). You will also need to ensure that field extractions are consistent between the default unix extractions and your data.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...