On my Linux server the universal forwarder and Splunk_TA_nix are installed, at least df and cpu are enabled in inputs.conf.
[script://./bin/df.sh]interval = 300sourcetype = dfsource = dfindex = osdisabled = 0
[script://./bin/cpu.sh]sourcetype = cpusource = cpu#interval = 30interval = 300index = osdisabled = 0
When I search for this Linux server on Splunk, I get df logs. But cpu logs are missing
Top 10 Values Count %df 44 1.224%
Could anyone advise? much appreciated.
View solution in original post
The cpu.sh was not running on the Linux server either as splunk or as root. It turned out that the cpu.sh has a dependency on sysstat package which I had not installed.
It is running now after sysstat was installed.