The answer is shown in this post: https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Unix-and-Linux-configuration/td-p/366783 You need to installed Splunk_TA_nix on all indexers/forwarders and searchhead. The search head needs Splunk_TA_nix to display data. Tks Louis.
... View more