Splunk Enterprise

Splunk_TA_nix interfaces.sh misses relevant IPv6-Adresses

bitnapper
Path Finder

Hi,

I have the Splunk_TA_nix installed and deployed. In generel it works. I activated the interfaces.sh which does give me IPv4-Adresses and IPv6 Link-Local-Adresses but none else. Since I have a primarily IPv6 environment I miss the most importent part but I don't understand why it delivers me the link-locals but not the public adresses?

I could not find any documentation or anything about activating ipv6 for the interfaces.sh and since there are link-locals I guess it is activated but the script has maybe a bug.

Can anyone tell me if theres a better documentation for this script anywhere or knows why it does not collect the ipv6 adresses?

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@bitnapper - interfaces.sh script internally using many commands depending on the flavor of Linux OS. (If you have to explore the journey yourself.)

Configured network interfaces via the shell commands dmesgethtoolifconfigkstatlanscanlanadmin, and netstat

(As per the documentation - https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About )

 

But regarding issue with the script, you can contact Splunk Support for the issue.

 

I hope this helps, Kindly upvote if it does!!!

bitnapper
Path Finder

I thought at least with a standard RHEL or Ubuntu it should work. So it seems I expected way to much. But when I have to maintain that for every upgrade, why do I need it? It seem I would be better of writing it myself when there so poorly maintained that even the most in uses *nixes aren't even decently supported?

Thanks for the link. I already had that but I thought that cant be all, is it?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@bitnapper - That's a Splunk support question. Please raise a support ticket if you think it's not working.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...