All Apps and Add-ons

cpu.sh diffent log format

stenbryggen
New Member

cpu.sh logs are different from universalforwarder then splunk installations.

Splunk is adding a line for all and each cpu, but the universalforwarder is adding everything in one log entry. And the "Hosts" dashboard can't understand the combined logs from the universalforwarder.

What can I do to fix this issue?

0 Karma

araitz
Splunk Employee
Splunk Employee

I'm not sure I understand. We use the universal forwarder to run the *nix TA, and there is fundamentaly no difference between the output from UF and from our indexers. My guess is that you don't have the TA installed on the search head, which is required so that muliti kv mode is enabled by default. See a similar issue here:

http://answers.splunk.com/answers/129893/splunk-app-for-unix-homemetrics-empty

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...