Getting Data In

Why are Services/processes missing from ps sourcetype query?

bsg273
Path Finder

I have Splunk_TA_nix installed and ps.sh enabled on my Apache storm nimbus instances.  I can run a general ps sourcetype query on a service I know should always be running like rhnsd and get events back just fine ...

 

 

index=os host="my-stormn-1" sourcetype=ps rhnsd

 

 

 However, when I do the same for the "stormnimbus" service I get zero events back ...

 

 

index=os host="my-stormn-1" sourcetype=ps stormnimbus

 

 

Meanwhile, a "sudo systemctl status stormnimbus" on the my-stormn-1 instance itself shows that it is active and running.  I'm having the same problem also with the stormui service as well as the stormsupervisor service running on my storm supervisor instances.  I should note that I do have Splunk_TA_nix installed on my splunk indexers.  Any advice as to why these services are not returning events with ps and how to fix it would be greatly appreciated.

Labels (5)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bsg273,

did you tried to manually debug the search?

in other words, running the search without the word "stormnimbus" is there a similar string?

maybe in the ps command output it has a different value (e.g. "storm nimbus").

You could manually search or use a part of the string (e.g. storm or nimbus) and see if the value is present in Splunk data.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...