All Apps and Add-ons

Splunk Add-On for Unix and Linux - UF doesn't send data from the "cpu_metric.sh" stanza?

Henri
Engager

Hi,

the initial situation is the following: I have an all-in-one instance, that simultaneously takes on the role of the DS, and a UF that sends its data to the AiO. The required stanzas were distributed as a separate app, in addition to the Linux TA via the DS. Scripted inputs from the TA like "vmstat.sh" or "netstat.sh" can be browsed on the AiO and work so far.

In the next step I wanted to activate the "cpu_metric.sh" stanza and proceeded like this:

1. I created a metric index on the AiO, called "linux_metrics".
2. I configured the inputs.conf under the "deployment-apps" on the AiO and enabled the stanza. This config was pushed to the UF, or rather it was pulled by the UF.

Config:
[script:///opt/splunkforwarder/etc/apps/Splunk_TA_nix/bin/cpu_metric.sh]
interval = 30
disabled = 0
index = linux_metrics

Unfortunately, however, no data ran into my metric index. "For fun" I tried the same procedure for other metric stanzas, which then immediately passed their data to the dedicated indexer.

Standard solutions, like installing sysstat, have already been tried.

Maybe one of you can think of something else. Thanks in advance.

Labels (2)
0 Karma
1 Solution

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Henri,

have you in the other index logs from cpu_metric.sh?

did you tried to delete (or comment) the cpu_metric.sh stanza in inputs.conf in both local and default folder of the TA_nix App, leaving only the input of the additional Add-On?

Ciao.

Giuseppe

0 Karma

Henri
Engager

Hi @gcusello, thanks for your quick response!

I tried your solution, but unfortunately it did not solve the problem either.

But I wanted to dig a little depper, so I started "cpu_metric.sh" and "cpu.sh" manually to check if they both work. Since they returned the same values, in the same format, I had the idea that "cpu_metric.sh" might not return metric data at all. I then created a dedicated event indexer and specified that for the stanza. Immediately the UF sent data concerning the stanza "cpu_metric.sh" to this indexer.

Short summary: It seems to work fine with an event indexer and "cpu_metric.sh" apparently doesn't send metric data.

But thanks again for your help 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Henri,

it's also my idea!

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...