We are using Splunk Cloud and we have a requirement to get the Linux performance counter data (CPU, Memory and Disk usage) from few Linux servers in our data center.
What we did is ;
“Splunk Add-on for Unix and Linux: Setup; Please set up this add-on on your forwarders. Documentation on how to configure this add-on is here”
Can some one tell me what is wrong here, why not getting the data.
When you say you installed the add-on on your cloud, do you mean the indexers or search heads? It should be installed on the indexers.
What index is the forwarder writing to? Does the index exist on the indexers?
That's a bad assumption. In SplunkCloud the indexers & search heads are usually separate. If you installed the TA on the search head, then you will still need to install it on the indexer.