All Apps and Add-ons

Splunk app for Unix and Linux: Why is the app not getting cpu or ram data?

ihiesbkalai
New Member

I configured the app but I am not getting any results for CPU or RAM when I preview index=os. I do get values but only for the host and not the forwarders and I followed all the documentation to set up the app and the addon. I am not getting the most crucial info.

0 Karma

Amandeepsin
New Member

Hi,

I am getting the same error. Can any one help me solving this

Nothing can been seen under sourcetype = cpu and vmstats but ps, hardware, df are working

Thanks,

0 Karma

zsanchez113
Explorer

Are you able to get any other data from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma

mhigginson
Explorer

Do you have the sysstat software package installed?

From the docs: http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Platformandhardwarerequirements
"What other items does the add-on require?
The Splunk Add-on for Unix and Linux requires the sysstat software package to function properly. You can download the sysstat utilities from the sysstat utilities download page or from your local package repository (depending on the version of *nix your host runs.)

On RHEL 7 and CentOS 7, the Splunk Add-on for Unix and Linux requires the net-tools software package to function properly. You can install the net-tools utilities from the OS' package repository using the command "sudo yum install net-tools"."

HiroshiSatoh
Champion

Did you also install add-ons on forwarders? Add-ons are also required on the forwarder side.
Also, have you got other logs (_internalt etc.) from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...