All Apps and Add-ons

Linux data collection

roopeshetty
Path Finder

Hi Guys,

We are using Splunk Cloud and we have a requirement to get the Linux performance counter data (CPU, Memory and Disk usage) from few Linux servers in our data center.

What we did is ;

  1. Installed the “Splunk Add-on for Unix and Linux” on our Splunk Cloud.
  2. Installed the “Splunk Add-on for Unix and Linux” on the universal forwarder of the Linux server and enabled the required scripts which we wanted to send the data of and then restarted the universal forwarder.
  3. Now we go to the App “Splunk Add-on for Unix and Linux” on our Splunk Cloud and we get the message as below;

“Splunk Add-on for Unix and Linux: Setup; Please set up this add-on on your forwarders. Documentation on how to configure this add-on is here”

Can some one tell me what is wrong here, why not getting the data.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When you say you installed the add-on on your cloud, do you mean the indexers or search heads? It should be installed on the indexers.
What index is the forwarder writing to? Does the index exist on the indexers?

---
If this reply helps you, Karma would be appreciated.
0 Karma

roopeshetty
Path Finder

its cloud splunk hence i assume its indexers+search heads both same there. index is main hence it exist there.

0 Karma

jnudell_2
Builder

That's a bad assumption. In SplunkCloud the indexers & search heads are usually separate. If you installed the TA on the search head, then you will still need to install it on the indexer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...