Splunk Enterprise

Splunk_TA_nix interfaces.sh misses relevant IPv6-Adresses

bitnapper
Path Finder

Hi,

I have the Splunk_TA_nix installed and deployed. In generel it works. I activated the interfaces.sh which does give me IPv4-Adresses and IPv6 Link-Local-Adresses but none else. Since I have a primarily IPv6 environment I miss the most importent part but I don't understand why it delivers me the link-locals but not the public adresses?

I could not find any documentation or anything about activating ipv6 for the interfaces.sh and since there are link-locals I guess it is activated but the script has maybe a bug.

Can anyone tell me if theres a better documentation for this script anywhere or knows why it does not collect the ipv6 adresses?

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@bitnapper - interfaces.sh script internally using many commands depending on the flavor of Linux OS. (If you have to explore the journey yourself.)

Configured network interfaces via the shell commands dmesgethtoolifconfigkstatlanscanlanadmin, and netstat

(As per the documentation - https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About )

 

But regarding issue with the script, you can contact Splunk Support for the issue.

 

I hope this helps, Kindly upvote if it does!!!

bitnapper
Path Finder

I thought at least with a standard RHEL or Ubuntu it should work. So it seems I expected way to much. But when I have to maintain that for every upgrade, why do I need it? It seem I would be better of writing it myself when there so poorly maintained that even the most in uses *nixes aren't even decently supported?

Thanks for the link. I already had that but I thought that cant be all, is it?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@bitnapper - That's a Splunk support question. Please raise a support ticket if you think it's not working.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...