All Apps and Add-ons

Splunk App for Unix not showing hosts from peered indexers...

samlll42
Explorer

Hi Everyone

Problem: On Splunk App for Unix (latest versions of all the components) on a search head I cannot see hosts from indexers peered to the search head. The data is there if I do a search on index=os ( I can see perf data for all the hosts: CPU, PS etc...), but in the dashboard I can only see the hosts indexed locally (local host and a forwarder). What am I doing wrong?

Example:

= splunk-search (local indexer and search-head) peered with splunk-indexer

=== splunk-forwarder X (forwarding to splunk-search)

=== splunk-forwarder Y (forwarding to splunk-search)

=splunk-indexer (local indexer)

=== splunk-forwarder A (forwarding to splunk-indexer)

=== splunk-forwarder B (forwarding to splunk-indexer)

=== splunk-forwarder C (forwarding to splunk-indexer)

If I go to Splunk App for Unix dashboard on splunk-indexer I can see hosts for:

  • splunk-indexer (local) + splunk-forwarder A, B, C (which is expected)

If I go to Splunk App for Unix dashboard on splunk-search I can only see hosts for:

  • splunk-search (local) + splunk-forwarder X,Y - NOT splunk-indexer, nor splunk-forwarder A, B and C

But when I do a search on splunk-search index=os I can see data being found for all hosts.

Do I need to setup Splunk App for Unix in a specific way to display data for remote/peered indexes?

Strunk
Explorer

See this question:

http://answers.splunk.com/answers/132477/adding-hosts-to-splunk-app-for-unix

What worked for me was following those instructions to ensure each host was added to a group, which was then added to a category. I'm guessing that because I deployed the app to the universal forwarders/deployment clients after installing the app on the deployment server/index, the categories and groups weren't populated automatically.

Strunk
Explorer

I'm having the same problem, with getting data back from universal forwarders. The data is making it to the indexer/deployment server, but it's not showing up in the dashboard.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...