Knowledge Management

Creating a script to gather machine performance

AleZ214
Loves-to-Learn

Hello, Ive been trying to set up a script to run every 5 minutes with cronjob in a CentOS enviorement

Heres the script and its configuration using cron

AleZ214_0-1716523226197.pngAleZ214_0-1716523226197.png

AleZ214_2-1716523349446.pngAleZ214_2-1716523349446.png

 

input.conf

AleZ214_1-1716523281823.pngAleZ214_1-1716523281823.png

This configuration is in my machine 3, configurated as UF
Already created system_metrics index in my Indexer GUI
When I try to search for "index=system_metrics sourcetype=linux_performance" in my machine 2 GUI configurated as SH theres no data, can someone help me or give me some instructions please? Thanks!

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AleZ214,

three questions (where the third could be the anwer of the second):

  • did you checked the grants and the user running your script?
  • how do you run your script, did you used the script command in inputs.conf?
  • why did you created your script, isn'rt  the script to have the same thing in the Splunk_TA_nix (https://splunkbase.splunk.com/app/833) sufficient for you?

in other words, if you cannot use the sript in the above app, see how it's managed and copy the approach for your.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...