What is the best way of getting Linux performance data into Splunk? Do we have to install the *nix app?
The nmon Tool is also a good start:
https://splunkbase.splunk.com/app/3947/ (app)
https://splunkbase.splunk.com/app/3948/ (TA)
https://splunkbase.splunk.com/app/3949/ (SA)
Documentation via:
https://www.octamis.com/metricator-docs/
You will want to install this app:
http://splunk-base.splunk.com/apps/22314/splunk-for-unix-and-linux
Reference the docs here for installation and usage instructions.
http://docs.splunk.com/Documentation/UnixApp/latest/User/AbouttheSplunkAppforUnix