Getting Data In

What are recommendations for monitoring information on a Linux server?

newbiesplunk
Path Finder

Hi,

I wish to monitor linux server info like number of CPU, processor, linux version etc in Splunk. What will be the recommended info to get from linux server and how do I do this? thks

Tags (2)
0 Karma
1 Solution

Gilberto_Castil
Splunk Employee
Splunk Employee

Your first step is to download and install the Splunk Universal Forwarder on the end point server that you wish to monitor. This is the preferred vehicle to read and upload data from your server to a Splunk Indexer. There are many types of helpful ways to figure out how to

  1. Install the Universal Forwarder and
  2. How to get data from Linux to a Splunk Indexer

To address your specific question, the best way to get started is to use the Splunk Add-on for Unix and Linux. This particular Add-on is configured on your the end point server that you wish to monitor. There is a detailed list of of the data obtained with this Add-on in the following link.

http://docs.splunk.com/Documentation/UnixAddOn/5.1.1/User/Whatdataarecollected

It is important to understand that the *NIX Add-on (above) is just part of the configuration of your Splunk Universal Forwarder. To complement the entire piece, you may want to use the Splunk App for Unix and Linux. This app is installed on your Splunk Indexer. This is documented in the following link.

http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix

I hope this helps,

-gc

View solution in original post

Gilberto_Castil
Splunk Employee
Splunk Employee

Your first step is to download and install the Splunk Universal Forwarder on the end point server that you wish to monitor. This is the preferred vehicle to read and upload data from your server to a Splunk Indexer. There are many types of helpful ways to figure out how to

  1. Install the Universal Forwarder and
  2. How to get data from Linux to a Splunk Indexer

To address your specific question, the best way to get started is to use the Splunk Add-on for Unix and Linux. This particular Add-on is configured on your the end point server that you wish to monitor. There is a detailed list of of the data obtained with this Add-on in the following link.

http://docs.splunk.com/Documentation/UnixAddOn/5.1.1/User/Whatdataarecollected

It is important to understand that the *NIX Add-on (above) is just part of the configuration of your Splunk Universal Forwarder. To complement the entire piece, you may want to use the Splunk App for Unix and Linux. This app is installed on your Splunk Indexer. This is documented in the following link.

http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix

I hope this helps,

-gc

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...