All Apps and Add-ons

Splunk Add-on for Unix and Linux - df.sh and cpu.sh result on index not parsed

rahmataw
Loves-to-Learn Lots

Hi, so I just try configure 1 Splunk Enterpise and 1 server installed with universal forwarder+ Splunk Add-on for Unix and Linux. When I check the event from Splunk server, I got this unusual result:

Screen Shot 2021-07-22 at 22.34.26.png

Screen Shot 2021-07-22 at 22.44.30.png

It is like my log not parsed, so there is no field about disk usage, cpu usage, etc. And because of that, when I use Splunk Apps for Unix and Linux for monitoring. I got below result:

Screen Shot 2021-07-22 at 22.42.39.png

 

How to solve this problem? I just follow the documentation and dont know how to solve this issue.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...