Will the Windows version of the "Splunk App for Unix and Linux" report on Linux metrics?
My Splunk Servers are Windows-based, but I need to report on the metrics from a Linux (Redhat/CentOS) system.
I installed the Splunk_TA_nix app in a Linux Splunk Universal Forwarder, and I have all the metrics coming over to my Windows indexer now.
Rather than build my own custom dashboards doing things like:
earliest=-1m index=os sourcetype=cpu | rex "\nall\s+(?<pctUser>\d+[.]\d+)\s+(?<pctNice>\d+[.]\d+)\s+(?<pctSystem>\d+[.]\d+)\s+(?<pctIowait>\d+[.]\d+)\s+(?<pctIdle>\d+[.]\d+)"
is there a Splunk app that would already do all of that under Windows?
The "Splunk App for Unix and Linux" can run on any server OS, its name should more accurately be "Splunk App for Unix and Linux data" or "Splunk App to supervise Unix and Linux". Once you have the TA up and running on your Linux forwarder, you can use that data any way you like on any Splunk on any OS.
The "Splunk App for Unix and Linux" can run on any server OS, its name should more accurately be "Splunk App for Unix and Linux data" or "Splunk App to supervise Unix and Linux". Once you have the TA up and running on your Linux forwarder, you can use that data any way you like on any Splunk on any OS.
Thanks! I just installed it and it works in my Windows Splunk server instance.