I have about a dozen hosts that I'm working on getting configured using the Splunk App for Unix and Linux. I've configured other hosts before and those work great, but these hosts are acting a bit weird.
When I use sourcetype=df, 11 out of the 12 hosts show up and work fine
When I use sourcetype=cpu, only 3 out of the 12 hosts show up and one of the three is the missing host from above
When I use sourcetype=vmstat, only 3 out of the 12 hosts show up and one of the three is the missing host from above
I've restarted, rebuilt, and still no luck. Thoughts?
Thanks Renjith!!! Your hints set me in the right direction. Turns out sysstat wasn't installed on most of the machines. Once it was installed everything is humming along just fine.
The first one (the df one), the problem host is a Darwin host and it reports the disk partitions differently. Just had to adjust the query to include that and presto! It works!
Oh.... and I've checked inputs.conf in Splunk_TA_nix/local and it is identical across all 12 servers.