All Apps and Add-ons

No display for "netstat" sourcetype for Solaris

broy32000
Explorer

We have splunk add-on for Unix installed. But it does not show any data for "netstat" sourcetype for Soalris clients. For Linux it does. Incidentally, Linuxhosts are indexers and heavy forwarders.

/app/splunk/splunkforwarder/etc/apps/Splunk_TA_nix/bin/netstat.sh is present in Solaris client, and it does output typical netstat like output.

Why are no data displayed in Splunk Web console?

Tags (1)
0 Karma

broy32000
Explorer

As per script compatibility table, https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Releasenotes
netstat is supported only for Linux. I am surprised because the script , netstat.sh works in Solaris

0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...