All Apps and Add-ons

SAI, why no metrics from Linux with collectd write_splunk plugin? But it seems HEC is receiving data.

yhu_splunk
Splunk Employee
Splunk Employee

I have Splunk App for Infrastructure installed and configured, it works for Windows agent, but I cannot make it for Linux server.

Collectd seems runs well with write_splunk plugin, I run search
index="_introspection" token| spath "data.token_name" | search "data.token_name"="collectd token"
looks the HEC is receiving data like the screenshot shows.
alt text
But there is no data of the metrics index assigned to the HEC token, and search for
| mstats count WHERE index=* AND metric_name=* by host, metric_name
only Windows host shows.
alt text

Labels (1)
Tags (1)
0 Karma
1 Solution

yhu_splunk
Splunk Employee
Splunk Employee

Solved, previously I select collectd_htttp as sourcetype, and it seems the em_metrics sourcetype is mandatory for collectd write_splunk plugin, change to em_metrics then solved.
em_metrics index is also mandatory for SAI, use other index then you have to adjust macros of SAI.

So, use em_metrics for both sourcetype and index.

View solution in original post

jasonstone
Explorer

OMG! I spent at least a day (off and on) trying to figure this out.
UGH.
Thank you so much!!!!!!

0 Karma

yhu_splunk
Splunk Employee
Splunk Employee

Solved, previously I select collectd_htttp as sourcetype, and it seems the em_metrics sourcetype is mandatory for collectd write_splunk plugin, change to em_metrics then solved.
em_metrics index is also mandatory for SAI, use other index then you have to adjust macros of SAI.

So, use em_metrics for both sourcetype and index.

Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...