All Apps and Add-ons

How to configure Splunk Universal Forwarder 6.2.4 to send data to NMON Performance Monitor for Unix and Linux Systems App?

s_abdulkhadar_j
New Member

Hi,

We have Splunk Indexer 6.2.4 and Universal Forwarders 6.2.4 on client machines.
Recently we have installed NMON Performance Monitor for Unix and Linux Systems (TA-nmon) app on Splunk indexer, but we are not seeing any option to add server class for forwarders in Forwarding and Receiving tab in Splunk indexer console.
Can anyone help to troubleshoot this and add the TA-nmon app in forwarders?

0 Karma

guilmxm
Influencer

Hi !

If you haven't yet, please take a look at Nmon documentation: http://nmon-for-splunk.readthedocs.io
You have video tutorial that will show you how to install and deploy: https://www.youtube.com/watch?v=-0H-CJDIGDI

On the instance(s) acting as search heads, install the Nmon performance core application.
If you want to get performance data from these search heads, also deploy the TA-nmon.
On standalone indexers, deploy the TA-nmon.
On clustered indexers, deploy the PA-nmon. (provided in the resources directory of the core app package)

On your deployment server, create a server class, associate with your Universal forwarders clients instances, and add the TA-nmon to be deployed. (enable restart splunkd)
You will have off course unarchived the TA-nmon package in $SPLUNK_HOME/etc/deployment-apps/

Let me know if this is unclear.

Guilhem

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...