Splunk Search

Splunk App for Unix and Linux props.conf fields are not calculated

nouraali
Explorer

Hi,

Given the below system architecture on a single server:

nouraali_3-1625581407952.png

 

1. When I pass the OS data generated by the Splunk addon (Splunk App for Unix and Linux) through the universal forwarder to Splunk single instance. I get fields like UsedBytes, PercentMemory, pctCPU,.. as below:

nouraali_0-1625580009335.png

 

2. But when I pass the OS data generated by the Splunk addon (Splunk App for Unix and Linux) through the universal forwarder to Cribl, then from Cribl to Splunk single instance.  These fields are not computed as below:

nouraali_1-1625580068541.png

 

As per my understanding, these extra fields are computed with the help of the props.conf file in the path /opt/SP/splunk/splunkforwarder/etc/apps/Splunk_TA_nix/default. But i don't get why this file is not taking effect or why the fields are not getting calculated when passed from UF to Cribl to Splunk.

 

Any idea how to pass the data from universal forwarder to Cribl then to Splunk(path no. 2) and get the extra fields to be calculated. 

 

Best Regards,

Noura Ali

 

 

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...