All Apps and Add-ons

Splunk_TA_nix on EC2 Instances

sloshburch
Ultra Champion

While playing with EC2 instances, I have the Splunk_TA_nix app deployed. The cpu.sh returns nothing because sar and mpstat are not found on the EC2 host.

I understand that Linux has other ways to pull in system metrics, but things are obviously simpler if the same Splunk_TA_nix could be used everywhere I have *nix.

Anyone solve this quirk?

0 Karma
1 Solution

wvonalt_splunk
Splunk Employee
Splunk Employee

@Burch - you've already hit the nail on the head... just install the war package on the system and the problem is solved.

View solution in original post

wvonalt_splunk
Splunk Employee
Splunk Employee

@Burch - you've already hit the nail on the head... just install the war package on the system and the problem is solved.

sloshburch
Ultra Champion

Oh, so manually install sar or mpstat? I was hoping we were just missing some other cpu command from our cpu.sh script 😞

0 Karma

sloshburch
Ultra Champion

Building off my own sillyness and expanding on @wvonalt answer:

Looks like it's as simple as yum install sysstat

0 Karma

sloshburch
Ultra Champion

My peers also hooked me up with this link, good to share here: http://docs.splunk.com/Documentation/UnixAddOn/latest/User/Whatdataarecollected

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...