All Apps and Add-ons

no unix folder under /opt/splunk/etc/apps

qubick
Path Finder

I installed "Splunk app for unix" by searching unix from "Find more apps" menu, based on the following instruction: http://answers.splunk.com/answers/50082/how-do-i-configure-a-splunk-forwarder-on-linux

And trying to copy /opt/splunk/etc/apps/unix according to the Step 8, because I hope my server(installed an indexer-instance of splunk) to be forwarded CPU/memory load (only two, not others) log data from other machines, but unable to find any folder named unix.

Is this the only way I could specify data I want them to be forwarded? Can I write a script into ~local/input (many from the forwarder not indexer) to specify data file related to CPU and memory load only, skipping copying ~/unix folder to the forwarder?

0 Karma
1 Solution

lukejadamec
Super Champion

It looks like that is an old post.

In the apps folder you will find 3 unix app components:

SA-nix

splunk_app_for_nix

Splunk_TA_nix

View solution in original post

lukejadamec
Super Champion

It looks like that is an old post.

In the apps folder you will find 3 unix app components:

SA-nix

splunk_app_for_nix

Splunk_TA_nix

lukejadamec
Super Champion

I expect you only need to transfer/copy the ones that contain inputs.conf files, but it would not hurt to transfer them all.

0 Karma

qubick
Path Finder

Thanks fount it, and does this mean I should copy all of those three to the forwarder. right?

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...