All Apps and Add-ons

Splunk App/Add-on for Unix and Linux not collecting data

bayman
Path Finder

Splunk Enterprise 6.5.1 installed for Indexer/Search head single instance server
Splunk Add-on for Unix and Linux 5.2.3 installed on a remote Linux server w/ UniversalForwarder installed
Splunk App for Unix and Linux 5.2.2 installed on Indexer/Search head

When i restart the universalforwarder after installing the Add-on on the remote linux server, I do not see an os index created on the indexer as suggested by the documentation.

I also copied the $SPLUNK_HOME/etc/apps/Splunk_TA_nix/default/inputs.conf to $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local/inputs.conf and enabled a few stanzas.

When I open the App from Splunk web, it just shows "Waiting for results.." and I don't see any data or even the host.

I am also getting the message: "Received event for unconfigured/disabled/deleted index=os with source="source::cpu" host="host::limelight" sourcetype="sourcetype::cpu". So far received events from 1 missing index(es)."

Do I need to manually create index=os somewhere?

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

Index has to be created on the Indexer/Search head. If you have installed the app/add-on on the indexer, you have to restart the indexer also to reflect the app.

Please check the following.

  • Is there an indexes.conf inside the /apps/Splunk_TA_nix/default and contain stanza with [os] ?
  • Have you restarted the indexer after installing this add-on ?
Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

Index has to be created on the Indexer/Search head. If you have installed the app/add-on on the indexer, you have to restart the indexer also to reflect the app.

Please check the following.

  • Is there an indexes.conf inside the /apps/Splunk_TA_nix/default and contain stanza with [os] ?
  • Have you restarted the indexer after installing this add-on ?
Happy Splunking!

bayman
Path Finder

I was not aware I had to install the add-on on the Indexer as well. Issue resolved.

0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...