Monitoring Splunk

Unix / Linux Addon

corina_kolb
Engager

Hello,

in many linux versions the comman netstat is now deprecated. Now you have the problem to use the sourcetype netstat within the Linux/Unix Addon in Splunk. Is there a possibility to use another command, e.g. ss instead of netstat in future as sourcetype? Many thanks in advance.

0 Karma

dave_null
Path Finder

Are you talking about this app? https://splunkbase.splunk.com/app/273/

 

If you have access to the app config files, you should be able to swap the netstat command with "ss," though I couldn't tell you exactly how without knowing which app you are referring to.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...