Archive
Highlighted

Splunk4JMX UniversalForwarder installation

Explorer

According to this question and answer:

http://splunk-base.splunk.com/answers/62185/where-to-install-splunk-for-jmx-app-in-a-distributed-spl...

The Splunk4JMX app needs to be split across different components as outlined in the answer.

I am confused about the installation of the app in the universal forwarder. Do I just copy the contents of:


SPLUNK4JMX/bin/*
SPLUNK4JMX/default/inputs.conf
SPLUNK4JMX/default/app.conf
SPLUNK4JMX/logs
SPLUNK4JMX/local

to


SplunkUniversalForwarder\etc\apps\

No other configuration required to enable the app on the forwarder side?

Obviously I need to enable the appropriate poll script in:

SPLUNK4JMX/default/inputs.conf

And add the details to in:

SPLUNK4JMX/bin/config/config.xml

But is that it? I am unfamiliar with the installation process of applications in the UniversalForwarder side so I am not sure if something else needs to be configured as well. Any clarification would be appreciated.

Thanks

Tags (2)
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Explorer

I cant seem to edit the question. the location should be:
SplunkUniversalForwarder/etc/apps

0 Karma
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Ultra Champion

On the Universal Forwarder side of the deployment you should have these files/folders :

SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/bin/*
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/inputs.conf
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/app.conf
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/logs
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/local

Then update your JMX configuration in SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/bin/config.xml

Then manually enable the poll script in SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/inputs.conf

Highlighted

Re: Splunk4JMX UniversalForwarder installation

Explorer

Hi Damien,
Can you please elaborate manually enable the poll script in SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/inputs.conf? Currently i have push the app through forwarder and configure the config.xml and also the outputs.conf in the Universal forwarder. however there is no data send to the indexer.

Thank you.
Alvin

0 Karma
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Ultra Champion

Updated instructions for version 2.4 of the App.

On the Universal Forwarder side of the deployment you should have these files/folders :

SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/bin/*
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/README/*
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/inputs.conf
SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/app.conf

Then update your JMX configuration in

SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/bin/config.xml

Then manually enable the modular input stanza in

SplunkUniversalForwarder/etc/apps/SPLUNK4JMX/default/inputs.conf 

by setting

disabled = 0
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Explorer

Hi Damien,

thank you for answering. we tried the exact config that you mentioned above, however there are still no data coming in to the index.

we have checked the the firewall is not blocking the port, the port in server side is opened, JVM can be monitored using jconsole.
other note: the UF and JVM is on Windows Server 2012

Is there any logs/config to check to figure this problem? (sorry, i am new to splunk)
thank you.

regards,
Alvin

0 Karma
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Ultra Champion

Error logs go to : index=_internal ExecProcessor error jmx.py

0 Karma
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Explorer

There is no message related to the installation in the forwarder.
Is there any steps that i missed?

Thank you

0 Karma
Highlighted

Re: Splunk4JMX UniversalForwarder installation

Ultra Champion

Have you fully followed the" troubleshooting" section steps in the docs ?

https://splunkbase.splunk.com/app/668/#/details

Other things to look at...

Can you get the App working correctly on a single standalone Splunk instance ? Perhaps you have not set up your forwarding correctly.

Do you have a python 2.7 runtime installed on the UF operating system and on the path for the Splunk user ? UFs (unlike Heavy Forwarders) don't ship with a python runtime.

Do you have the correct Java 1.7+ runtime installed on the UF operating system and on the path for the Splunk user ?

Highlighted

Re: Splunk4JMX UniversalForwarder installation

Explorer

Thanks Damien,

seems like the issue is caused by not having python and Java 1.7+ installed

0 Karma