All Apps and Add-ons

Splunk app for Unix and Linux: Why is the app not getting cpu or ram data?

ihiesbkalai
New Member

I configured the app but I am not getting any results for CPU or RAM when I preview index=os. I do get values but only for the host and not the forwarders and I followed all the documentation to set up the app and the addon. I am not getting the most crucial info.

0 Karma

Amandeepsin
New Member

Hi,

I am getting the same error. Can any one help me solving this

Nothing can been seen under sourcetype = cpu and vmstats but ps, hardware, df are working

Thanks,

0 Karma

zsanchez113
Explorer

Are you able to get any other data from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma

mhigginson
Explorer

Do you have the sysstat software package installed?

From the docs: http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Platformandhardwarerequirements
"What other items does the add-on require?
The Splunk Add-on for Unix and Linux requires the sysstat software package to function properly. You can download the sysstat utilities from the sysstat utilities download page or from your local package repository (depending on the version of *nix your host runs.)

On RHEL 7 and CentOS 7, the Splunk Add-on for Unix and Linux requires the net-tools software package to function properly. You can install the net-tools utilities from the OS' package repository using the command "sudo yum install net-tools"."

HiroshiSatoh
Champion

Did you also install add-ons on forwarders? Add-ons are also required on the forwarder side.
Also, have you got other logs (_internalt etc.) from the forwarder?

0 Karma

Amandeepsin
New Member

yes. getting other logs but not for cpu and memory. For ps, harware, disk it is working fine
can you please help

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...