Getting Data In

What are recommendations for monitoring information on a Linux server?

newbiesplunk
Path Finder

Hi,

I wish to monitor linux server info like number of CPU, processor, linux version etc in Splunk. What will be the recommended info to get from linux server and how do I do this? thks

Tags (2)
0 Karma
1 Solution

Gilberto_Castil
Splunk Employee
Splunk Employee

Your first step is to download and install the Splunk Universal Forwarder on the end point server that you wish to monitor. This is the preferred vehicle to read and upload data from your server to a Splunk Indexer. There are many types of helpful ways to figure out how to

  1. Install the Universal Forwarder and
  2. How to get data from Linux to a Splunk Indexer

To address your specific question, the best way to get started is to use the Splunk Add-on for Unix and Linux. This particular Add-on is configured on your the end point server that you wish to monitor. There is a detailed list of of the data obtained with this Add-on in the following link.

http://docs.splunk.com/Documentation/UnixAddOn/5.1.1/User/Whatdataarecollected

It is important to understand that the *NIX Add-on (above) is just part of the configuration of your Splunk Universal Forwarder. To complement the entire piece, you may want to use the Splunk App for Unix and Linux. This app is installed on your Splunk Indexer. This is documented in the following link.

http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix

I hope this helps,

-gc

View solution in original post

Gilberto_Castil
Splunk Employee
Splunk Employee

Your first step is to download and install the Splunk Universal Forwarder on the end point server that you wish to monitor. This is the preferred vehicle to read and upload data from your server to a Splunk Indexer. There are many types of helpful ways to figure out how to

  1. Install the Universal Forwarder and
  2. How to get data from Linux to a Splunk Indexer

To address your specific question, the best way to get started is to use the Splunk Add-on for Unix and Linux. This particular Add-on is configured on your the end point server that you wish to monitor. There is a detailed list of of the data obtained with this Add-on in the following link.

http://docs.splunk.com/Documentation/UnixAddOn/5.1.1/User/Whatdataarecollected

It is important to understand that the *NIX Add-on (above) is just part of the configuration of your Splunk Universal Forwarder. To complement the entire piece, you may want to use the Splunk App for Unix and Linux. This app is installed on your Splunk Indexer. This is documented in the following link.

http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix

I hope this helps,

-gc

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...