All Apps and Add-ons

Splunk app for Unix and Linux: Why is the app not getting cpu or ram data?

ihiesbkalai
New Member

I configured the app but I am not getting any results for CPU or RAM when I preview index=os. I do get values but only for the host and not the forwarders and I followed all the documentation to set up the app and the addon. I am not getting the most crucial info.

0 Karma

Amandeepsin
New Member

Hi,

I am getting the same error. Can any one help me solving this

Nothing can been seen under sourcetype = cpu and vmstats but ps, hardware, df are working

Thanks,

0 Karma

zsanchez113
Explorer

Are you able to get any other data from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma

mhigginson
Explorer

Do you have the sysstat software package installed?

From the docs: http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Platformandhardwarerequirements
"What other items does the add-on require?
The Splunk Add-on for Unix and Linux requires the sysstat software package to function properly. You can download the sysstat utilities from the sysstat utilities download page or from your local package repository (depending on the version of *nix your host runs.)

On RHEL 7 and CentOS 7, the Splunk Add-on for Unix and Linux requires the net-tools software package to function properly. You can install the net-tools utilities from the OS' package repository using the command "sudo yum install net-tools"."

HiroshiSatoh
Champion

Did you also install add-ons on forwarders? Add-ons are also required on the forwarder side.
Also, have you got other logs (_internalt etc.) from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...