All Apps and Add-ons

Splunk App for Unix - Host listed multiple times in the category/grouping list

mikelanghorst
Motivator

When configuring Categories and groups in the UI for the Unix app, I find nearly every host listed multiple times in the "hosts not in group" column. Many of them are listed 4-6 times.

Any idea what's causing this? Are there any differences to which I select?

1 Solution

jspears
Communicator

From http://docs.splunk.com/Documentation/UnixApp/latest/User/First-timeconfiguration#Settings:_Categorie...

When making host assignments, note the
following:

  • You can only assign hosts to a group. When you do this, the Splunk App for Unix and Linux automatically assigns the hosts to the category that contains the group.
  • You can assign hosts to more than one group at a time. However, each group must be a member of a separate category.

Maybe you've added hosts to multiple categories?

View solution in original post

mikelanghorst
Motivator

Definitely a browser issue. I tried last night with the exact same path. Macbook Air -> VMWare View Client -> Windows7 & Chrome. No issues this time.

No worries Alex, with so many around and I hadn't seen you since at least Feb. at the office.

0 Karma

araitz
Splunk Employee
Splunk Employee

Thanks Mike, just let us know if it pops back up. By the way, I just this minute realized that I saw you twice at conf, and you even said hi to me, but I didn't recognize you without your cowboy hat and/or rodeo gear! I totally apologize, mea culpa 🙂

0 Karma

mikelanghorst
Motivator

I've went back in today, and I'm only seeing one. It seems to be likely a browser issue. I originally had this behavior while using Chrome/Win7 via VMWare VDI session. I'm not seeing this on Firefox/Fedora, nor from the same VDI session, though I have rebooted that session since. I'll try again tonight from the exact same setup.

0 Karma

araitz
Splunk Employee
Splunk Employee

Mike - can you open a support case? Please let me know so I can take a look at your diag. FYI, we get this data from the metadata command as such:

 | metadata type=hosts `os_index`
0 Karma

jspears
Communicator

From http://docs.splunk.com/Documentation/UnixApp/latest/User/First-timeconfiguration#Settings:_Categorie...

When making host assignments, note the
following:

  • You can only assign hosts to a group. When you do this, the Splunk App for Unix and Linux automatically assigns the hosts to the category that contains the group.
  • You can assign hosts to more than one group at a time. However, each group must be a member of a separate category.

Maybe you've added hosts to multiple categories?

mikelanghorst
Motivator

Realized I wasn't clear when stating hosts are listed twice.

When creating the group, under the "Hosts not in group" column, hostnames are listed multiple times here.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...