All Apps and Add-ons

Installed Splunk App for Unix and Linux, but why isnt the app reporting on any of my unix hosts?

triralph
New Member

I installed this app on my splunk server, I've enabled the app but I can't find documentation on what to do next for this app. My unix host behind it don't show up under host in this app. Do I need another app installed on my unix servers to make this work?

0 Karma

malmoore
Splunk Employee
Splunk Employee

As @ChrisG says, you can reference the documentation to find out what to do after installing the app. The quickest path to getting data in is to:

  1. Set up your main instance as a receiver.
  2. Install universal forwarders on any unix hosts that you want to see in the app.
  3. Configure the forwarders to send data to the receiver.
  4. Install the Splunk Add-on for Unix and Linux on the forwarders on each unix host.
  5. Configure the add-on to send the data that you want.
  6. Confirm no firewall blocks traffic between the unix hosts and the receiving indexer. The management port (8089) and receiving ports on the host with the app must be able to be reached from any host you want to send data to the app.
  7. Wait, then confirm data comes in.
  8. Configure the Splunk App for Unix and Linux.

Even more reading:
* Install the Splunk App for Unix and Linux in a distributed environment

Hope this helps.

ChrisG
Splunk Employee
Splunk Employee

The documentation is here: http://docs.splunk.com/Documentation/UnixApp/5.0.1/User/AbouttheSplunkAppforUnix . Perhaps you have not installed the add-on? See What a Splunk App for Unix and Linux deployment looks like in the docs.

triralph
New Member

I've got Splunk Add-on for *Nix and Splunk App for Unix installed on my splunk. If I'm missing something help me out.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Have you configured the inputs on the Splunk Add-on for *nix? You can do so from right within Splunk Web. Just activate the add-on from the Apps page.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...