All Apps and Add-ons

SOS 2.3.0 on Splunk 5

andrey2007
Contributor

I have Splunk 5 on Windows, today i installed SOS 2.3.0, but i do not see graphs in Resource Usage>Splunk CPU/Memory Usage, only No results found. Inspect ...
Did somebody have the same problem and what`s way to resolve problem?

hexx
Splunk Employee
Splunk Employee

Today we have published a maintenance release (2.3.1) of the S.o.S app to address certain compatibility issues with Splunk 5.x. I encourage you to test this new version which will hopefully resolve any problems you currently are experiencing.

MuS
Legend

hi andrey2007

I have S.o.S. now running for some time on Splunk 5 and had no problem. what do the logs report?

cheers,

MuS

MuS
Legend

yes this is for sure the reason for not getting any data. Try to run the powershell.cmd ps_sos.ps1 command manually as the user how runs splunk

0 Karma

andrey2007
Contributor

from splunkd.log
ERROR ExecProcessor - message from ""D:\Program Files\Splunk\etc\apps\sos\bin\sospowershell.cmd" ps_sos.ps1" "Powershell" \xAD\xA5 \xEF\xA5\xE2\xE1\xEF \xA2\xAD\xE3\xE2७\xAD\xA5\xA9 \xA8\xAB\xA8 \xA2\xAD\xA5譥\xA9
i think this is reason, but what does it mean?
what version of SOS sshould i follow for splunk start working?

0 Karma

MuS
Legend

I just followed the instruction and it works for me.
again my question: what does splunkd.log reports about S.o.S. App?

0 Karma

andrey2007
Contributor

i saw this file but there nothing about splunk 5 and SOS 2.3.0

0 Karma

MuS
Legend

well how about splunkd.log?
did you follow the $SPLUNK_HOME/etc/apps/sos/README for the setup?

0 Karma

andrey2007
Contributor

What logs? Should i set windows event log as input?

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...