All Apps and Add-ons

Splunk app for Unix and Linux: Why is the app not getting cpu or ram data?

ihiesbkalai
New Member

I configured the app but I am not getting any results for CPU or RAM when I preview index=os. I do get values but only for the host and not the forwarders and I followed all the documentation to set up the app and the addon. I am not getting the most crucial info.

0 Karma

Amandeepsin
New Member

Hi,

I am getting the same error. Can any one help me solving this

Nothing can been seen under sourcetype = cpu and vmstats but ps, hardware, df are working

Thanks,

0 Karma

zsanchez113
Explorer

Are you able to get any other data from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma

mhigginson
Explorer

Do you have the sysstat software package installed?

From the docs: http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Platformandhardwarerequirements
"What other items does the add-on require?
The Splunk Add-on for Unix and Linux requires the sysstat software package to function properly. You can download the sysstat utilities from the sysstat utilities download page or from your local package repository (depending on the version of *nix your host runs.)

On RHEL 7 and CentOS 7, the Splunk Add-on for Unix and Linux requires the net-tools software package to function properly. You can install the net-tools utilities from the OS' package repository using the command "sudo yum install net-tools"."

HiroshiSatoh
Champion

Did you also install add-ons on forwarders? Add-ons are also required on the forwarder side.
Also, have you got other logs (_internalt etc.) from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...