All Apps and Add-ons

Installed Splunk App for Unix and Linux, but why isnt the app reporting on any of my unix hosts?

triralph
New Member

I installed this app on my splunk server, I've enabled the app but I can't find documentation on what to do next for this app. My unix host behind it don't show up under host in this app. Do I need another app installed on my unix servers to make this work?

0 Karma

malmoore
Splunk Employee
Splunk Employee

As @ChrisG says, you can reference the documentation to find out what to do after installing the app. The quickest path to getting data in is to:

  1. Set up your main instance as a receiver.
  2. Install universal forwarders on any unix hosts that you want to see in the app.
  3. Configure the forwarders to send data to the receiver.
  4. Install the Splunk Add-on for Unix and Linux on the forwarders on each unix host.
  5. Configure the add-on to send the data that you want.
  6. Confirm no firewall blocks traffic between the unix hosts and the receiving indexer. The management port (8089) and receiving ports on the host with the app must be able to be reached from any host you want to send data to the app.
  7. Wait, then confirm data comes in.
  8. Configure the Splunk App for Unix and Linux.

Even more reading:
* Install the Splunk App for Unix and Linux in a distributed environment

Hope this helps.

ChrisG
Splunk Employee
Splunk Employee

The documentation is here: http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix . Perhaps you have not installed the add-on? See What a Splunk App for Unix and Linux deployment looks like in the docs.

triralph
New Member

I've got Splunk Add-on for *Nix and Splunk App for Unix installed on my splunk. If I'm missing something help me out.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Have you configured the inputs on the Splunk Add-on for *nix? You can do so from right within Splunk Web. Just activate the add-on from the Apps page.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...