Deployment Architecture

monitor linux processes

karthikbalakris
Explorer

hi all,
How do i monitor the processes that are running on Linux similar to monitoring services in windows. in windows i use WMI:SERVICES to do. but i am not sire of the correct way to do it on Linux processes. Kindly help.

Tags (3)

dwaddle
SplunkTrust
SplunkTrust

As you know, Linux does not have WMI. The closest thing that is easy to the deploy is the Splunk App for Linux and Unix. This supports a ps data input which you can use to monitor processes.

If this app doesn't give you exactly what you want out of the box, you can always roll your own scripted input.

martin_mueller
SplunkTrust
SplunkTrust

The *NIX app has a number of useful inputs, such as scripts calling top and ps periodically.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...