All Apps and Add-ons

Splunk Nmon app OStype not populating for AIX

jpagan
Explorer

We are using the TA-nmon add on. We only use the light forwarder on our AIX hosts and therefore do not have python on these lpars. However, Perl is installed. I configured the TA to use the nmon2csv.pl instead of the python version.

I am getting some data in the dashboards now, but OStype is not being extracted correctly So the AIX hosts only appear under "Any Hosts" but not under "AIX" when the AIX radio button is selected in a dashboard. Linux hosts are using nmon2csv.py and those dashboards are working fine. Only AIX does not work.

Any ideas how to fix?

1 Solution

guilmxm
Influencer

Hi,

The OStype filtering uses a lookup table which is by default generated each night at 1h AM (lookup nmon_inventory, generated by a scheduled search)

After adding new hosts, you can manually generate the lookup table by running the report: "Generate NMON Inventory Lookup Table"
Once the lookup table has been generated, you should find your AIX hosts in inventory interfaces "CONFIG: Hosts Simple Inventory"

If you find your AIX hosts in the inventory interface, then OStype filtering will work as expected.

Note: If you are running a cluster, the lookup table must be updated or synced in each search head. If you're using search head clustering from 6.2, this is automatic. In non sh clustering, you can set to run in one search head then sync it to other search heads.

View solution in original post

guilmxm
Influencer

Hi,

The OStype filtering uses a lookup table which is by default generated each night at 1h AM (lookup nmon_inventory, generated by a scheduled search)

After adding new hosts, you can manually generate the lookup table by running the report: "Generate NMON Inventory Lookup Table"
Once the lookup table has been generated, you should find your AIX hosts in inventory interfaces "CONFIG: Hosts Simple Inventory"

If you find your AIX hosts in the inventory interface, then OStype filtering will work as expected.

Note: If you are running a cluster, the lookup table must be updated or synced in each search head. If you're using search head clustering from 6.2, this is automatic. In non sh clustering, you can set to run in one search head then sync it to other search heads.

jpagan
Explorer

Thanks. You were spot on, everything was working this morning!

0 Karma

guilmxm
Influencer

Great 🙂

You're welcome

If you like the App, don't hesitate to rate it, i like stars 🙂

jpagan
Explorer

Done. Rated - 5 stars. Thanks again!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...