All Apps and Add-ons

I am not recieving anything in splunk app for unix and linux. what can i do to resolve it?

anshuman19
Explorer

I installed the Splunk add-on for unix and Linux on my Linux machine which have forwarder installed in it and installed splunk app for unix and Linux in windows which is the receiver but I am not receiving any thing in my splunk app, the setting in APP is as follows:
UNIX INDEX
index=main
index=os
SYSLOG DATA

sourcetype=syslog
CPU DATA
sourcetype=Linux_CPUTime
sourcetype=cpu
DF DATA
sourcetype=df
When I run setup.sh it ask username and password I enter my username and password and then a menu open which have certain options I choose
Manage *nix inputs
and then it again open menu
so I choose enable all inputs
but then it gives me error
"ENABLING FAILED"
I cant figure out what is the problem can anyone help me out.

0 Karma

p_gurav
Champion

Hi,

In below doc link, you can try "Enable the data and scripted inputs with configuration files" section.
http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Enabledataandscriptedinputs

Also did you restart splunk after enabling input?

0 Karma

anshuman19
Explorer

I already gone through the docs.
restart splunk enterprise or UF?
I installed Splunk add for unix on splunk enterprise also but it says:
This server is not running a known Unix or Linux operating system. Install this add-on on Unix or Linux systems only.

0 Karma

p_gurav
Champion

restart universal forwarder. Also what OS you have of the system where you indexing data from UF, is it windows?

0 Karma

anshuman19
Explorer

yes windows.

0 Karma

anshuman19
Explorer

restarted the universal forwarder but nothing received.

0 Karma

p_gurav
Champion

Check out this solution:

https://answers.splunk.com/answers/237809/why-am-i-getting-this-error-trying-to-configure-th.html

Also check internal log for any errors, and try searching index=os or index=main in Searching and reporting app.

Also you need to install ad-on on forwarder and search head both.

0 Karma

anshuman19
Explorer

How to install add-on on search head?
http://docs.splunk.com/Documentation/UnixAddOn/5.2.0/User/DeploytheSplunkAdd-onforUnixandLinuxinadis...
In above doc its mentioned that splunk app for unix to be installed on search head that I have already done.
but I want to confirm here that splunk enterprise is refered here as search head?

0 Karma

p_gurav
Champion

Please go through this doc to check where you need to install add-on and app:

https://docs.splunk.com/Documentation/UnixApp/5.2.3/User/DeploytheSplunkAppforUnixandLinuxinadistrib...

0 Karma

anshuman19
Explorer

ok so in my case I have splunk enterprise installed in windows which in my knowledge is both the indexed and search head and Splunk app for unix is also installed on splunk enterprise , and universal forwarder is installed in Ubuntu with splunk addon installed . My forwarder is working as I can see data coming in through Forwarders: Instance in default dashboard.
I have not defined any indexer in splunk enterprise, now coming to my Linux machine which have universal forwarder to install Splunk addon for unix I moved my unpacked downloaded files to $SPLUNK_HOME/etc/apps and restarted.
Now for enabling script and data input I used below command
$SPLUNK_HOME/bin/splunk cmd $SPLUNK_HOME/etc/apps/Splunk_TA_nix/bin/setup.sh
which directed me to the menu page and given me the enabling failed error as I mentioned above.
So this the whole thing I have done.I am not sure about the

1)Install the Splunk App for Unix and Linux on an indexer
2)Install the Splunk App for Unix and Linux on a search head
in http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/DeploytheSplunkAdd-onforUnixandLinuxinadis...
as I have only one forwarder so I don't think I have to do any thing for 1 and 2.
Now please tell me what is wrong and how t solve the issue.

0 Karma

p_gurav
Champion

Hi,

ok. Now install Splunk_TA_nix on your search head like you install unix app. Also can you check forwarder's internal logs. Also try to configure input using configuration files(inputs.conf in unix add-on on forwarder) instead setup.sh.

0 Karma

anshuman19
Explorer

I have doubt search head here is splunk enterprise right? Because I have only one forwarder.
I already installed it in my splunk enterprise( installed in windows )but it says "This server is not running a known Unix or Linux operating system. Install this add-on on Unix or Linux systems only. "

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...