Hello,
in many linux versions the command netstat is now deprecated.
Now you have the problem to use the sourcetype netstat within the Linux/Unix Addon in Splunk.
Is there a possibility to use another command, e.g. ss instead of netstat in future as sourcetype? Many thanks in advance.
Yours sincerely
Corina Kolb
Use the add-on as a template to create your own add-on that uses ss instead of netstat.
Use the add-on as a template to create your own add-on that uses ss instead of netstat.
Hi,
thanks at all. This helps very much. We have made an Add-On with the comand ss.
Yours sincerely
Corina Kolb