All Apps and Add-ons

Splunk Add-On for Unix and Linux - UF doesn't send data from the "cpu_metric.sh" stanza?

Henri
Engager

Hi,

the initial situation is the following: I have an all-in-one instance, that simultaneously takes on the role of the DS, and a UF that sends its data to the AiO. The required stanzas were distributed as a separate app, in addition to the Linux TA via the DS. Scripted inputs from the TA like "vmstat.sh" or "netstat.sh" can be browsed on the AiO and work so far.

In the next step I wanted to activate the "cpu_metric.sh" stanza and proceeded like this:

1. I created a metric index on the AiO, called "linux_metrics".
2. I configured the inputs.conf under the "deployment-apps" on the AiO and enabled the stanza. This config was pushed to the UF, or rather it was pulled by the UF.

Config:
[script:///opt/splunkforwarder/etc/apps/Splunk_TA_nix/bin/cpu_metric.sh]
interval = 30
disabled = 0
index = linux_metrics

Unfortunately, however, no data ran into my metric index. "For fun" I tried the same procedure for other metric stanzas, which then immediately passed their data to the dedicated indexer.

Standard solutions, like installing sysstat, have already been tried.

Maybe one of you can think of something else. Thanks in advance.

Labels (2)
0 Karma
1 Solution

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Henri,

have you in the other index logs from cpu_metric.sh?

did you tried to delete (or comment) the cpu_metric.sh stanza in inputs.conf in both local and default folder of the TA_nix App, leaving only the input of the additional Add-On?

Ciao.

Giuseppe

0 Karma

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Henri,

it's also my idea!

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...