All Apps and Add-ons

Splunk App for Unix and Linux: Why doesn't the app create index, sourcetypes, or anything necessary in order to work normally?

adepasquale
Path Finder

I was finally able to get data into the "os" index by creating it manually, but none of the source types exist. I see the data in a preview, but in the dashboards, nothing works.

0 Karma
1 Solution

mrybar
Explorer

Do you also have the TA installed?

The way I have understood it in the past is that the search head application will lay the groundwork for the indexes, sourcetypes, etc. No data will be populated in those areas until the TA puts the proper props.conf in place. Hope that helps.

View solution in original post

mrybar
Explorer

Do you also have the TA installed?

The way I have understood it in the past is that the search head application will lay the groundwork for the indexes, sourcetypes, etc. No data will be populated in those areas until the TA puts the proper props.conf in place. Hope that helps.

ChrisG
Splunk Employee
Splunk Employee

Yes, you need to deploy the add-on onto your Unix systems. See What a Splunk App for Unix and Linux deployment looks like in the documentation.

adepasquale
Path Finder

Yes, i was missing the TA on the search head even though it was installed on the remote hosts.

Sort of misleading since when you install the TA it says in big red letters (do not install on non *nix)

0 Karma

thejeffreystone
Path Finder

Thats strange. I just installed it on a new 6.5 instance and the only thing I had to do was enable the metrics I wanted to see in the Splunk_TA_nix.

0 Karma

thejeffreystone
Path Finder

So you see data in preview but not in sourcetypes, and you have the TA on the remote server. Sounds like the sourcetype and possibly field extractions might not have been created either. Especially if you can see the data in a query outside the app. Either that or it could be a permissions issues I guess if your account doesn't have access to some of the data, but that seems unlikely since you see the data in preview.

0 Karma

adepasquale
Path Finder

I'm using 6.3 on a windows server with information being forwarded via the add on from a remote unix server.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...