Splunk Search

Splunk App for Unix and Linux props.conf fields are not calculated

nouraali
Explorer

Hi,

Given the below system architecture on a single server:

nouraali_3-1625581407952.png

 

1. When I pass the OS data generated by the Splunk addon (Splunk App for Unix and Linux) through the universal forwarder to Splunk single instance. I get fields like UsedBytes, PercentMemory, pctCPU,.. as below:

nouraali_0-1625580009335.png

 

2. But when I pass the OS data generated by the Splunk addon (Splunk App for Unix and Linux) through the universal forwarder to Cribl, then from Cribl to Splunk single instance.  These fields are not computed as below:

nouraali_1-1625580068541.png

 

As per my understanding, these extra fields are computed with the help of the props.conf file in the path /opt/SP/splunk/splunkforwarder/etc/apps/Splunk_TA_nix/default. But i don't get why this file is not taking effect or why the fields are not getting calculated when passed from UF to Cribl to Splunk.

 

Any idea how to pass the data from universal forwarder to Cribl then to Splunk(path no. 2) and get the extra fields to be calculated. 

 

Best Regards,

Noura Ali

 

 

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...