All Apps and Add-ons

SAI, why no metrics from Linux with collectd write_splunk plugin? But it seems HEC is receiving data.

yhu_splunk
Splunk Employee
Splunk Employee

I have Splunk App for Infrastructure installed and configured, it works for Windows agent, but I cannot make it for Linux server.

Collectd seems runs well with write_splunk plugin, I run search
index="_introspection" token| spath "data.token_name" | search "data.token_name"="collectd token"
looks the HEC is receiving data like the screenshot shows.
alt text
But there is no data of the metrics index assigned to the HEC token, and search for
| mstats count WHERE index=* AND metric_name=* by host, metric_name
only Windows host shows.
alt text

Labels (1)
Tags (1)
0 Karma
1 Solution

yhu_splunk
Splunk Employee
Splunk Employee

Solved, previously I select collectd_htttp as sourcetype, and it seems the em_metrics sourcetype is mandatory for collectd write_splunk plugin, change to em_metrics then solved.
em_metrics index is also mandatory for SAI, use other index then you have to adjust macros of SAI.

So, use em_metrics for both sourcetype and index.

View solution in original post

jasonstone
Explorer

OMG! I spent at least a day (off and on) trying to figure this out.
UGH.
Thank you so much!!!!!!

0 Karma

yhu_splunk
Splunk Employee
Splunk Employee

Solved, previously I select collectd_htttp as sourcetype, and it seems the em_metrics sourcetype is mandatory for collectd write_splunk plugin, change to em_metrics then solved.
em_metrics index is also mandatory for SAI, use other index then you have to adjust macros of SAI.

So, use em_metrics for both sourcetype and index.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...