All Apps and Add-ons

Splunk for VMware Forwarder Appliance and *nix app

colinj
Path Finder

Howdy all,

I've got the Forwarder Appliance for Splunk for VMware up and running and I was hoping to monitor its behavior via Splunk. Since it is basically a Linux (CentOS) vm I have enabled the *nix app on it which seems to be working, for the most part. However there seem to be some data that are missing. It looks like neither sar or iostat are available on the FA. What this means is that I cannot collect cpu stats (among other things) from the FA. My reason for wanting this data is so that I can see how loaded the FA is and so that I can make a case for increasing its resources (CPU and RAM) if it is overloaded.

So, what's the right way to get all of the *nix app inputs to work properly on the FA?

0 Karma
1 Solution

colinj
Path Finder

Well, here's what I did to solve this at least in the short run.

  1. Found the necessary package with yum. yum whatprovides *bin/sar
  2. Installed the necessary package with yum. sudo yum install sysstat-7.0.2-12.el5.x86_64

View solution in original post

colinj
Path Finder

Well, here's what I did to solve this at least in the short run.

  1. Found the necessary package with yum. yum whatprovides *bin/sar
  2. Installed the necessary package with yum. sudo yum install sysstat-7.0.2-12.el5.x86_64

bbingham
Builder

We simply were cutting as many packages as possible that weren't needed by the FA. We elected to cut most of these, because you can collect the same data for the FA using the normal perf collection of the app. If there's a compelling reason, we can make sure it's in there.

0 Karma

colinj
Path Finder

So now my question is, was this package left off of the FA intentionally? If so why? Can it be included in future releases of the FA?

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...