All Apps and Add-ons

Splunk App for Infrastructure Installation Problem

roysoham85
New Member

We are using a trial version of Splunk to test how best it fits our enterprise.
I installed the addon Splunk App For Infrastrucure on debian jessie 8.2
Splunk is available on port http://(hostname):8000
I used HEC port to send metrics as 8088
I used the receiver port as 9997
The recommended script was used for installation.
The mgmt port 8090 was found to be open,
All the steps ran through, the last step was
Step:Configure agent...
Nothing happened after that.
I tried to re-run the script, I was returned with the message:
Unable to create symlink='/etc/systemd/system/multi-user.target.wants/SplunkForwarder.service' : File exists
Questions from my side:
As per the entity addition instruction, we should receive a confirmation of connection of new entities, however nothing happens.
Once the script finishes running, verify your data connection.
It may take up to 5 minutes to show entities in the UI.
No new entities connected yet...

How will I know that the entity is connected?
Is there any alternate way to check out the CPU usage.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Did you try troubleshooting docs? I will check collectd.logs and check if collectd is installed (apt-cache policy collectd) and if it is running.
https://docs.splunk.com/Documentation/InfraApp/1.4.0/Admin/DataCollection

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...