All Apps and Add-ons

Splunk App and Add-on for Unix and Linux –– add-on specific fields are not being extracted, which is breaking the dashboards

chris_jepeway
New Member

I've got the Splunk Add-on for Unix and Linux installed on my index master and across my 3 indexers via a cluster bundle.

In the App for Unix & Linux running on my search head, I can see results from all 4 hosts, text like the output from cpu.sh and ps.sh.

But none of the add-on specific fields, e.g., pctCPU from top.sh, are being extracted, which of course breaks many of the associated dashboards.

Any help on getting the app & add-ons working, and in particular, fixing field extraction, across the cluster would be very much appreciated.

0 Karma
1 Solution

harsmarvania57
SplunkTrust
SplunkTrust

Hi @chris.jepeway,

To achieve this field extraction on search head you need to install Splunk Add-on for Unix and Linux (Splunk_TA_nix) on search head because field extraction (props.conf) and field transformation (transforms.conf) is available in Add-on to break those fields not in App.

Thanks,
Harshil

View solution in original post

harsmarvania57
SplunkTrust
SplunkTrust

Hi @chris.jepeway,

To achieve this field extraction on search head you need to install Splunk Add-on for Unix and Linux (Splunk_TA_nix) on search head because field extraction (props.conf) and field transformation (transforms.conf) is available in Add-on to break those fields not in App.

Thanks,
Harshil

chris_jepeway
New Member

Ah, perfect, it works!

Um, what did I miss when I didn't understand I needed the TA as well as the app? Is that the usual case, e.g.? That I'll need to install a TA as well as an app, whenever both exist, on search heads? Or is this a special case for the Nix app & TA?

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

This depends on case by case, for some of the application you require TA and app both on search heads and for some of the application only app is require.

0 Karma

chris_jepeway
New Member

And, it's worth pointing out that I'm trying to work through installing the app by using tar to extract the tarball into $SPLUNK_HOME/etc/{apps,master-apps} myself, and then copying configs out of default/ and into /local. I've set up inputs.conf (change to disabled = 0) and indexes.conf (add repFactor = auto)...but it seems I'm missing some setup.

I'll try an "install from file" and see what I get.

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>