Splunk IT Service Intelligence

How to Transfer Data to ITSI With Splunk Add-on for Unix and Linux

hoangpt
Explorer

Hi everyone, I'm having some trouble and really need your help.

Currently, I'm deploying ITSI Splunk service and using Add-on for Unix and Linux on Splunk. The problem is that when I send data to ITSI, ITSI didn't receive any Entity 

splunk.png

Untitled.png

 
 

 

Down here is my configuration on Add-on for Unix and Linux : 

Screenshot 2020-10-11 160646.png

 
 

 

Also, my Splunk Enterprise has collected Linux log by Universal Forwarder . I don't know what is the problem with my ITSI. Please help me.

Labels (2)
0 Karma

hoangpt
Explorer

11.pngMy configuration on Add-on for Unix and Linux

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...