All Apps and Add-ons

Installed Splunk App for Unix and Linux, but why isnt the app reporting on any of my unix hosts?

triralph
New Member

I installed this app on my splunk server, I've enabled the app but I can't find documentation on what to do next for this app. My unix host behind it don't show up under host in this app. Do I need another app installed on my unix servers to make this work?

0 Karma

malmoore
Splunk Employee
Splunk Employee

As @ChrisG says, you can reference the documentation to find out what to do after installing the app. The quickest path to getting data in is to:

  1. Set up your main instance as a receiver.
  2. Install universal forwarders on any unix hosts that you want to see in the app.
  3. Configure the forwarders to send data to the receiver.
  4. Install the Splunk Add-on for Unix and Linux on the forwarders on each unix host.
  5. Configure the add-on to send the data that you want.
  6. Confirm no firewall blocks traffic between the unix hosts and the receiving indexer. The management port (8089) and receiving ports on the host with the app must be able to be reached from any host you want to send data to the app.
  7. Wait, then confirm data comes in.
  8. Configure the Splunk App for Unix and Linux.

Even more reading:
* Install the Splunk App for Unix and Linux in a distributed environment

Hope this helps.

ChrisG
Splunk Employee
Splunk Employee

The documentation is here: http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix . Perhaps you have not installed the add-on? See What a Splunk App for Unix and Linux deployment looks like in the docs.

triralph
New Member

I've got Splunk Add-on for *Nix and Splunk App for Unix installed on my splunk. If I'm missing something help me out.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Have you configured the inputs on the Splunk Add-on for *nix? You can do so from right within Splunk Web. Just activate the add-on from the Apps page.

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...