Splunk Search

inputs.conf entry to get linux operating system name and version

jcorcoran508
Path Finder

Greetings -

I do have the TA for nix.

I spend a couple of hours scouring all my resources and looking at the TA_nix  where to insert or turn an entry for the OS type.

On the linux side need to know if what vendor :  centos/RHEL ,  version 6,7,8 .

Any input would be appreciated.

Labels (1)
0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

sourcetype=Unix:Version has a bunch of the fields (os_*) you are looking for. I am not sure the distribution name is part of that dataset, since there is no standard way of figuring that out across all *nix platforms. Do have that sourcetype in your indexed data?

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee

sourcetype=Unix:Version has a bunch of the fields (os_*) you are looking for. I am not sure the distribution name is part of that dataset, since there is no standard way of figuring that out across all *nix platforms. Do have that sourcetype in your indexed data?

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...