All Apps and Add-ons

Splunk App for Unix and Linux: After configuring hosts, why are some hosts not showing up for these 3 sourcetypes?

dbcase
Motivator

Hi,

I have about a dozen hosts that I'm working on getting configured using the Splunk App for Unix and Linux. I've configured other hosts before and those work great, but these hosts are acting a bit weird.

When I use sourcetype=df, 11 out of the 12 hosts show up and work fine
When I use sourcetype=cpu, only 3 out of the 12 hosts show up and one of the three is the missing host from above
When I use sourcetype=vmstat, only 3 out of the 12 hosts show up and one of the three is the missing host from above

I've restarted, rebuilt, and still no luck. Thoughts?

0 Karma
1 Solution

renjith_nair
Legend

Hello @dbcase,

  • Check the splunkd logs on the hosts which haven't turned up. You should be able to find hints for your problem
  • Try to execute the script manually from the hosts and see if it's throwing any error. Most probably the basic package which is used by the scripts might be missing from the hosts, for eg: sysstat
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Hello @dbcase,

  • Check the splunkd logs on the hosts which haven't turned up. You should be able to find hints for your problem
  • Try to execute the script manually from the hosts and see if it's throwing any error. Most probably the basic package which is used by the scripts might be missing from the hosts, for eg: sysstat
---
What goes around comes around. If it helps, hit it with Karma 🙂

dbcase
Motivator

Thanks Renjith!!! Your hints set me in the right direction. Turns out sysstat wasn't installed on most of the machines. Once it was installed everything is humming along just fine.

The first one (the df one), the problem host is a Darwin host and it reports the disk partitions differently. Just had to adjust the query to include that and presto! It works!

Thank you!!!

dbcase
Motivator

Oh.... and I've checked inputs.conf in Splunk_TA_nix/local and it is identical across all 12 servers.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...