All Apps and Add-ons

Splunk App and Add-on for Unix and Linux –– add-on specific fields are not being extracted, which is breaking the dashboards

chris_jepeway
New Member

I've got the Splunk Add-on for Unix and Linux installed on my index master and across my 3 indexers via a cluster bundle.

In the App for Unix & Linux running on my search head, I can see results from all 4 hosts, text like the output from cpu.sh and ps.sh.

But none of the add-on specific fields, e.g., pctCPU from top.sh, are being extracted, which of course breaks many of the associated dashboards.

Any help on getting the app & add-ons working, and in particular, fixing field extraction, across the cluster would be very much appreciated.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @chris.jepeway,

To achieve this field extraction on search head you need to install Splunk Add-on for Unix and Linux (Splunk_TA_nix) on search head because field extraction (props.conf) and field transformation (transforms.conf) is available in Add-on to break those fields not in App.

Thanks,
Harshil

View solution in original post

harsmarvania57
Ultra Champion

Hi @chris.jepeway,

To achieve this field extraction on search head you need to install Splunk Add-on for Unix and Linux (Splunk_TA_nix) on search head because field extraction (props.conf) and field transformation (transforms.conf) is available in Add-on to break those fields not in App.

Thanks,
Harshil

chris_jepeway
New Member

Ah, perfect, it works!

Um, what did I miss when I didn't understand I needed the TA as well as the app? Is that the usual case, e.g.? That I'll need to install a TA as well as an app, whenever both exist, on search heads? Or is this a special case for the Nix app & TA?

0 Karma

harsmarvania57
Ultra Champion

This depends on case by case, for some of the application you require TA and app both on search heads and for some of the application only app is require.

0 Karma

chris_jepeway
New Member

And, it's worth pointing out that I'm trying to work through installing the app by using tar to extract the tarball into $SPLUNK_HOME/etc/{apps,master-apps} myself, and then copying configs out of default/ and into /local. I've set up inputs.conf (change to disabled = 0) and indexes.conf (add repFactor = auto)...but it seems I'm missing some setup.

I'll try an "install from file" and see what I get.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...