Splunk Search

Splunk App for Unix and Linux props.conf fields are not calculated

nouraali
Explorer

Hi,

Given the below system architecture on a single server:

nouraali_3-1625581407952.png

 

1. When I pass the OS data generated by the Splunk addon (Splunk App for Unix and Linux) through the universal forwarder to Splunk single instance. I get fields like UsedBytes, PercentMemory, pctCPU,.. as below:

nouraali_0-1625580009335.png

 

2. But when I pass the OS data generated by the Splunk addon (Splunk App for Unix and Linux) through the universal forwarder to Cribl, then from Cribl to Splunk single instance.  These fields are not computed as below:

nouraali_1-1625580068541.png

 

As per my understanding, these extra fields are computed with the help of the props.conf file in the path /opt/SP/splunk/splunkforwarder/etc/apps/Splunk_TA_nix/default. But i don't get why this file is not taking effect or why the fields are not getting calculated when passed from UF to Cribl to Splunk.

 

Any idea how to pass the data from universal forwarder to Cribl then to Splunk(path no. 2) and get the extra fields to be calculated. 

 

Best Regards,

Noura Ali

 

 

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...