- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Installed Splunk App for Unix and Linux, but why isnt the app reporting on any of my unix hosts?
I installed this app on my splunk server, I've enabled the app but I can't find documentation on what to do next for this app. My unix host behind it don't show up under host in this app. Do I need another app installed on my unix servers to make this work?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

As @ChrisG says, you can reference the documentation to find out what to do after installing the app. The quickest path to getting data in is to:
- Set up your main instance as a receiver.
- Install universal forwarders on any unix hosts that you want to see in the app.
- Configure the forwarders to send data to the receiver.
- Install the Splunk Add-on for Unix and Linux on the forwarders on each unix host.
- Configure the add-on to send the data that you want.
- Confirm no firewall blocks traffic between the unix hosts and the receiving indexer. The management port (8089) and receiving ports on the host with the app must be able to be reached from any host you want to send data to the app.
- Wait, then confirm data comes in.
- Configure the Splunk App for Unix and Linux.
Even more reading:
* Install the Splunk App for Unix and Linux in a distributed environment
Hope this helps.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


The documentation is here: http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix . Perhaps you have not installed the add-on? See What a Splunk App for Unix and Linux deployment looks like in the docs.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've got Splunk Add-on for *Nix and Splunk App for Unix installed on my splunk. If I'm missing something help me out.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Have you configured the inputs on the Splunk Add-on for *nix? You can do so from right within Splunk Web. Just activate the add-on from the Apps page.
