Hi, so I just try configure 1 Splunk Enterpise and 1 server installed with universal forwarder+ Splunk Add-on for Unix and Linux. When I check the event from Splunk server, I got this unusual result:
It is like my log not parsed, so there is no field about disk usage, cpu usage, etc. And because of that, when I use Splunk Apps for Unix and Linux for monitoring. I got below result:
How to solve this problem? I just follow the documentation and dont know how to solve this issue.