All Apps and Add-ons

Splunk App for Infrastructure Installation Problem

roysoham85
New Member

We are using a trial version of Splunk to test how best it fits our enterprise.
I installed the addon Splunk App For Infrastrucure on debian jessie 8.2
Splunk is available on port http://(hostname):8000
I used HEC port to send metrics as 8088
I used the receiver port as 9997
The recommended script was used for installation.
The mgmt port 8090 was found to be open,
All the steps ran through, the last step was
Step:Configure agent...
Nothing happened after that.
I tried to re-run the script, I was returned with the message:
Unable to create symlink='/etc/systemd/system/multi-user.target.wants/SplunkForwarder.service' : File exists
Questions from my side:
As per the entity addition instruction, we should receive a confirmation of connection of new entities, however nothing happens.
Once the script finishes running, verify your data connection.
It may take up to 5 minutes to show entities in the UI.
No new entities connected yet...

How will I know that the entity is connected?
Is there any alternate way to check out the CPU usage.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Did you try troubleshooting docs? I will check collectd.logs and check if collectd is installed (apt-cache policy collectd) and if it is running.
https://docs.splunk.com/Documentation/InfraApp/1.4.0/Admin/DataCollection

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...