All Apps and Add-ons

Splunk App for Unix and Linux: Why is the app not showing memory info?

ralphw_SAIC
Path Finder

I am trying to get the Splunk App for Unix and Linux to show memory information and it does not show anything. I have verified that vmstats is running and sending information. I can search on sourcetype=vmstat and receive info for the servers.

Any help would be appreciated on how to rectify this issue.

macado
New Member

I'm running into same issue, any ideas? I see plenty of data if I do sourcetype=vmstat but under dashboard I get unknown - is vmstat.sh enabled?

0 Karma

amielke
Communicator

We had the same problem, in the sourcetype vmstats were data. In the sourcetype cpu or df were no data. Verify that the os sysstat package is installed. After that we had data in both sourcetypes.

ralphw_SAIC
Path Finder

sysstat is installed on the systems. the issue isn't that we are not receiving information for those sourcetypes. we get them when we search for them, we just don't get them in the app for unix/linux even though the sourcetypes are configured in the app.

0 Karma

mattymo
Splunk Employee
Splunk Employee

my bad for the quick read of the issue.

if you go into the Splunk for *nix app, and go to settings >> your data >> Memory data

are you set to sourcetype=vmstat?

If so, when you hit the preview button, do any events return?

Perhaps try hitting save on that page again?

Also, can you advise where in the app you are looking? Both on the home page and on the hosts page? What do you see for the hosts page when in table view?

- MattyMo
0 Karma

ralphw_SAIC
Path Finder

sourcetype=vmstat and doing a preview I do get the vmstat data.

I am looking at it both from the home page, metrics page, and hosts page. It shows nothing. The hosts page says both memory and disk is unknown and asks if they are enabled, which they are.

0 Karma

jiaqya
Builder

Ralph, Did you get an solution for this issue . i am kind of facing same issue.. its there in the sourcetypes, but not on home/metrics or hosts...

0 Karma

sufi
Engager

Anyone found any solution for this? I am also facing the same issue.

0 Karma

mattymo
Splunk Employee
Splunk Employee

+1 for making sure sysstat is installed!

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...