On my Linux server the universal forwarder and Splunk_TA_nix are installed, at least df and cpu are enabled in inputs.conf.
vi /opt/splunkforwarder/etc/apps/Splunk_TA_nix/local/inputs.conf
[script://./bin/df.sh]
interval = 300
sourcetype = df
source = df
index = os
disabled = 0
[script://./bin/cpu.sh]
sourcetype = cpu
source = cpu
#interval = 30
interval = 300
index = os
disabled = 0
When I search for this Linux server on Splunk, I get df logs. But cpu logs are missing
Top 10 Values Count %
df 44 1.224%
Could anyone advise? much appreciated.
Thanks soutamo,
The cpu.sh was not running on the Linux server either as splunk or as root. It turned out that the cpu.sh has a dependency on sysstat package which I had not installed.
It is running now after sysstat was installed.
I ran into this problem and while the dependency for cpu.sh is to have sysstat installed, I also found that df.sh wouldn't parse correctly on Ubuntu until the gawk package was installed (mawk package was already present).
Gord T.