All Apps and Add-ons

Splunk add-on for Unix and Linux - netstat, logs fields not extracted

faustf
Communicator

Hi guys,
I installed the Splunk App for Unix and Linux and the Splunk Add-on for Unix and Linux.

I've a problem with the sourcetype = netstat . The fields of these events aren't automatically extracted.
If I search (in verbose mode): "index=os sourcetype=netstat" this is the result:
alt text
As you can see the fields: "Proto Recv-Q Send-Q LocalAddress ForeignAddress State" are not extracted.

Instead, if I search (in verbose mode): "index=os sourcetype=iostat" this is the result is fine:
alt text

Thanks

0 Karma
1 Solution

faustf
Communicator

I've just figured out that that this is a duplicated post
The solution is to use the | multikv command in the query:

index=os sourcetype=netstat | multikv

View solution in original post

0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

To make this automatic, you can add the following to your props.conf on the search head:

[netstat]
KV_MODE = multi
0 Karma

mikaellindstrom
New Member

I know this is an answered ticket but shouldn't it be fixed in the add-on so that it's automatically available to anyone without doing any manual configuration changes?

0 Karma

faustf
Communicator

I've just figured out that that this is a duplicated post
The solution is to use the | multikv command in the query:

index=os sourcetype=netstat | multikv
0 Karma

vumanhtai
Path Finder

yeah! i like your command

0 Karma

amielke
Communicator

We have the similar problem, check that the package sysstat is installed at the operation system.

0 Karma

faustf
Communicator

I checked and the sysstat package was already installed, also there are statistical logs in /var/log/sa/

The OS is Centos 6.8

0 Karma

amielke
Communicator

Which distribution is it?

0 Karma

faustf
Communicator
  • Splunk Enterprise Server 6.5.2
  • Splunk App for Unix splunk_app_for_nix 5.2.2
  • Splunk Add-on for *Nix Splunk_TA_nix 5.2.3
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...