Getting Data In

TA-nmon fifo_reader.py, fifo_reader.sh, nmon.fifo not running, permission denied

tbrown
Path Finder

The TA-nmon is not sending data to 'nmon' index on my splunk instance. I was looking through the troubleshoot guide for TA-nmon and I noticed that the forwarder was not running any of the three expected running processes (fifo_reader.py, fifo_reader.sh, nmon.fifo) when I ran a 'ps -ef | egrep nmon'. I tried starting these processes manually but it returned the message:

 

 

couldn't run "/opt/osi/splunkforwarder/etc/apps/TA-nmon/bin/nmon_helper.sh": Permission denied

 

 

I saw another solution to this issue where the user changed the permissions for these exectuables, how would I do that? 

Labels (2)
0 Karma

tbrown
Path Finder

Disregard the question, I gave permissions to these processes and they are running correctly now. Additionally, data is being sent to the 'nmon' index in Splunk which is good, but it is only sending the following data:

tbrown_0-1593454802492.png

Why are none of the metrics being forwarded?

When I try to start nmon using:

/opt/splunkforwarder/bin/splunk cmd /opt/splunkforwarder/etc/apps/TA-nmon/bin/nmon_helper.sh

 It gives the error:

ERROR nmon:diskgroup file - failed to find disk=fd0 for group=fd0 disks known=16

and stalls there until I manually cancel it. I assume this is the issue, how would i fix this.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...