We are using the Splunk Add-on for Unix on all of our Unix and Linux servers. But lots of the scripts are quit old and fail on new operating releases like Solaris 11 whit ldoms and Zones, Redhat 7, Oracle Linux. We have adopted some of the scripts, but is quit a tedious work.
Has Splunk some plans to update this app, or are there other people around which face the same issue and are interested in some form of collaboration in updating this scripts?
I've the same concern as well. Though Unix systems are so important, the regexes are basic and they assign everything to "syslog" as sourcetype. Wish they had more specific sourcetypes and more cleaner approach for such an important TA