All Apps and Add-ons

Has S.o.S TA for UNIX been tested on AIX?

sjnorman
Explorer

I'm trying to deploy S.o.S TA for UNIX on a universal forwarded deployed to an AIX 6.1.0.0 instance in order to troubleshoot why the splunkd process is consistently consuming between 25% and 50% of our CPU.

I've extracted the tgz file under the "apps" directory, created a local inputs.conf with the various options enabled, and re-started the universal forwarder but no events are being forwarded.

I manually ran some of the bash scripts under the TA-sos bin directory and none of them are working properly. For the common.sh, I had to remove the case condition for it to work properly. For ps_sos.sh, running it gives the following error:

awk: 0602-521 There is a regular
expression error.
[] imbalance.

The source line number is 1. The
error context is
{NR == 1 && $0 = header} {sub("^", "", $1); if
(NF>12) {args=$13; for (j=14; j<=NF;
j++) args = args "
" $j} else
args=""; sub("^[^\134[: -]*/",
"", >>> $12) <<<

There appears to be a issue with the FORMAT variable that is being set.

Any ideas on how to get this running properly?

0 Karma
1 Solution

hexx
Splunk Employee
Splunk Employee

Although I cannot directly help you to make ps_sos.sh work on AIX, I can at least confirm that we have not tested this scripted input on AIX and therefore we don't expect it to work on that platform, unfortunately.

View solution in original post

hexx
Splunk Employee
Splunk Employee

Although I cannot directly help you to make ps_sos.sh work on AIX, I can at least confirm that we have not tested this scripted input on AIX and therefore we don't expect it to work on that platform, unfortunately.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...