All Apps and Add-ons

Splunk App and Add-on for Unix and Linux –– add-on specific fields are not being extracted, which is breaking the dashboards

chris_jepeway
New Member

I've got the Splunk Add-on for Unix and Linux installed on my index master and across my 3 indexers via a cluster bundle.

In the App for Unix & Linux running on my search head, I can see results from all 4 hosts, text like the output from cpu.sh and ps.sh.

But none of the add-on specific fields, e.g., pctCPU from top.sh, are being extracted, which of course breaks many of the associated dashboards.

Any help on getting the app & add-ons working, and in particular, fixing field extraction, across the cluster would be very much appreciated.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @chris.jepeway,

To achieve this field extraction on search head you need to install Splunk Add-on for Unix and Linux (Splunk_TA_nix) on search head because field extraction (props.conf) and field transformation (transforms.conf) is available in Add-on to break those fields not in App.

Thanks,
Harshil

View solution in original post

harsmarvania57
Ultra Champion

Hi @chris.jepeway,

To achieve this field extraction on search head you need to install Splunk Add-on for Unix and Linux (Splunk_TA_nix) on search head because field extraction (props.conf) and field transformation (transforms.conf) is available in Add-on to break those fields not in App.

Thanks,
Harshil

chris_jepeway
New Member

Ah, perfect, it works!

Um, what did I miss when I didn't understand I needed the TA as well as the app? Is that the usual case, e.g.? That I'll need to install a TA as well as an app, whenever both exist, on search heads? Or is this a special case for the Nix app & TA?

0 Karma

harsmarvania57
Ultra Champion

This depends on case by case, for some of the application you require TA and app both on search heads and for some of the application only app is require.

0 Karma

chris_jepeway
New Member

And, it's worth pointing out that I'm trying to work through installing the app by using tar to extract the tarball into $SPLUNK_HOME/etc/{apps,master-apps} myself, and then copying configs out of default/ and into /local. I've set up inputs.conf (change to disabled = 0) and indexes.conf (add repFactor = auto)...but it seems I'm missing some setup.

I'll try an "install from file" and see what I get.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...