All Apps and Add-ons

Splunk App for Infrastructure Installation Problem

roysoham85
New Member

We are using a trial version of Splunk to test how best it fits our enterprise.
I installed the addon Splunk App For Infrastrucure on debian jessie 8.2
Splunk is available on port http://(hostname):8000
I used HEC port to send metrics as 8088
I used the receiver port as 9997
The recommended script was used for installation.
The mgmt port 8090 was found to be open,
All the steps ran through, the last step was
Step:Configure agent...
Nothing happened after that.
I tried to re-run the script, I was returned with the message:
Unable to create symlink='/etc/systemd/system/multi-user.target.wants/SplunkForwarder.service' : File exists
Questions from my side:
As per the entity addition instruction, we should receive a confirmation of connection of new entities, however nothing happens.
Once the script finishes running, verify your data connection.
It may take up to 5 minutes to show entities in the UI.
No new entities connected yet...

How will I know that the entity is connected?
Is there any alternate way to check out the CPU usage.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Did you try troubleshooting docs? I will check collectd.logs and check if collectd is installed (apt-cache policy collectd) and if it is running.
https://docs.splunk.com/Documentation/InfraApp/1.4.0/Admin/DataCollection

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...