All Apps and Add-ons

Splunk Add-On for Unix and Linux - UF doesn't send data from the "cpu_metric.sh" stanza?

Henri
Engager

Hi,

the initial situation is the following: I have an all-in-one instance, that simultaneously takes on the role of the DS, and a UF that sends its data to the AiO. The required stanzas were distributed as a separate app, in addition to the Linux TA via the DS. Scripted inputs from the TA like "vmstat.sh" or "netstat.sh" can be browsed on the AiO and work so far.

In the next step I wanted to activate the "cpu_metric.sh" stanza and proceeded like this:

1. I created a metric index on the AiO, called "linux_metrics".
2. I configured the inputs.conf under the "deployment-apps" on the AiO and enabled the stanza. This config was pushed to the UF, or rather it was pulled by the UF.

Config:
[script:///opt/splunkforwarder/etc/apps/Splunk_TA_nix/bin/cpu_metric.sh]
interval = 30
disabled = 0
index = linux_metrics

Unfortunately, however, no data ran into my metric index. "For fun" I tried the same procedure for other metric stanzas, which then immediately passed their data to the dedicated indexer.

Standard solutions, like installing sysstat, have already been tried.

Maybe one of you can think of something else. Thanks in advance.

Labels (2)
0 Karma
1 Solution

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Henri,

have you in the other index logs from cpu_metric.sh?

did you tried to delete (or comment) the cpu_metric.sh stanza in inputs.conf in both local and default folder of the TA_nix App, leaving only the input of the additional Add-On?

Ciao.

Giuseppe

0 Karma

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Henri,

it's also my idea!

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...