Getting Data In

Trying to monitor local macOS system logs and performance data as remote log from Ubuntu instance on VirtualBox

Herman
Explorer

I am trying to get my Ubuntu instance on VirtualBox to ingest my mac's system logs and performance data as remote logs.

I already installed the add-on for linux and unix and configured the forwarding host as 10.0.2.255:9997 on my Mac and receiving port as 9997 on the Ubuntu instance. 

I edited the input.config of the add-on for linux and unix and enable all the metrics and put the 'index = mac' on every one of them.

I already added the index 'mac' for the admin on the ubuntu instance. However, when I searched 'index = mac' on the ubuntu instance, there is no data. 

Is there something important that I am missing? Any help would be appreciated as this is really important as this will determine whether I will have the opportunity. Many thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...