All Apps and Add-ons

Splunk Add-On for Unix and Linux - UF doesn't send data from the "cpu_metric.sh" stanza?

Henri
Engager

Hi,

the initial situation is the following: I have an all-in-one instance, that simultaneously takes on the role of the DS, and a UF that sends its data to the AiO. The required stanzas were distributed as a separate app, in addition to the Linux TA via the DS. Scripted inputs from the TA like "vmstat.sh" or "netstat.sh" can be browsed on the AiO and work so far.

In the next step I wanted to activate the "cpu_metric.sh" stanza and proceeded like this:

1. I created a metric index on the AiO, called "linux_metrics".
2. I configured the inputs.conf under the "deployment-apps" on the AiO and enabled the stanza. This config was pushed to the UF, or rather it was pulled by the UF.

Config:
[script:///opt/splunkforwarder/etc/apps/Splunk_TA_nix/bin/cpu_metric.sh]
interval = 30
disabled = 0
index = linux_metrics

Unfortunately, however, no data ran into my metric index. "For fun" I tried the same procedure for other metric stanzas, which then immediately passed their data to the dedicated indexer.

Standard solutions, like installing sysstat, have already been tried.

Maybe one of you can think of something else. Thanks in advance.

Labels (2)
0 Karma
1 Solution

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Henri,

have you in the other index logs from cpu_metric.sh?

did you tried to delete (or comment) the cpu_metric.sh stanza in inputs.conf in both local and default folder of the TA_nix App, leaving only the input of the additional Add-On?

Ciao.

Giuseppe

0 Karma

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Henri,

it's also my idea!

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...