All Apps and Add-ons

SOS tool not pulling from OS index

hartfoml
Motivator

I have inherited 6 indexers in my deployment.

Some of the SoS searches don't work because they are pulling data from the SoS index. All of the indexers are running PS commands for the NIX app into index=os and only three of them are running PS command script into the index=SoS. if I run the SoS searches and change the index=os the search comes back with data.

What would be the best way to handle this

1) turn off/uninstall the NIX app on all the indexers and reinstall the SOS app
2) edit the SOS app to search both the SOS index and the OS index

Also is it too much to have both the SOS app running slimier system request scripts as the NIX app?

0 Karma

grantjansen
Explorer

No need to do either choice.
Read this response in regards to "What do I need to do for the SoS data inputs to track Splunk resource usage?" here: http://answers.splunk.com/answers/38091/best-practices-to-deploy-the-sos-app-in-a-distributed-search...

Enabling these scripts should start the data flowing into your SOS index.

0 Karma
Get Updates on the Splunk Community!

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Want a chance to win $500 to the Splunk shop? Take our IT Incident Management Survey!

  Top Trends & Best Practices in Incident ManagementSplunk is partnering up with Constellation Research to ...