Getting Data In

How to get all system logs like CPU, disk, and memory from a Splunk forwarder machine?

Explorer

Hi,

I want to get all system logs, like CPU, Disk, Memory and other system logs, from machine where my Splunk forwarder installed on a Linux machine.

Right now, I can only see CPU/DISK/Machine log from Splunk host machine, not from all my clients.

Can you help me? What do I have to set up?

Thanks

0 Karma

SplunkTrust
SplunkTrust

You can install Splunk TA for Linux app on your forwarders (I believe you've this app installed on your Splunk servers already).

https://splunkbase.splunk.com/app/833/#/overview

SplunkTrust
SplunkTrust

Are you running the Splunk for Unix app?

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Explorer

Yes into Linux box.
I have input files like this :

[monitor:///apps/eqpricer/logs]
whitelist = stdout.log$|server.log$
index = myapppricer
sourcetype = myapp
log

0 Karma