All Apps and Add-ons

Splunk App for Unix and Linux: Why doesn't the app create index, sourcetypes, or anything necessary in order to work normally?

adepasquale
Path Finder

I was finally able to get data into the "os" index by creating it manually, but none of the source types exist. I see the data in a preview, but in the dashboards, nothing works.

0 Karma
1 Solution

mrybar
Explorer

Do you also have the TA installed?

The way I have understood it in the past is that the search head application will lay the groundwork for the indexes, sourcetypes, etc. No data will be populated in those areas until the TA puts the proper props.conf in place. Hope that helps.

View solution in original post

mrybar
Explorer

Do you also have the TA installed?

The way I have understood it in the past is that the search head application will lay the groundwork for the indexes, sourcetypes, etc. No data will be populated in those areas until the TA puts the proper props.conf in place. Hope that helps.

ChrisG
Splunk Employee
Splunk Employee

Yes, you need to deploy the add-on onto your Unix systems. See What a Splunk App for Unix and Linux deployment looks like in the documentation.

adepasquale
Path Finder

Yes, i was missing the TA on the search head even though it was installed on the remote hosts.

Sort of misleading since when you install the TA it says in big red letters (do not install on non *nix)

0 Karma

thejeffreystone
Path Finder

Thats strange. I just installed it on a new 6.5 instance and the only thing I had to do was enable the metrics I wanted to see in the Splunk_TA_nix.

0 Karma

thejeffreystone
Path Finder

So you see data in preview but not in sourcetypes, and you have the TA on the remote server. Sounds like the sourcetype and possibly field extractions might not have been created either. Especially if you can see the data in a query outside the app. Either that or it could be a permissions issues I guess if your account doesn't have access to some of the data, but that seems unlikely since you see the data in preview.

0 Karma

adepasquale
Path Finder

I'm using 6.3 on a windows server with information being forwarded via the add on from a remote unix server.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...