All,
I just enabled the time input for Splunk_TA_nix and I am getting data. But I don't see any extractions. I dug into the Splunk App and I dont see that there are any. was there another app I need to install for this? Can anyone tell me what my field extractions are for setting up the NTP dashboard in Splunk ES?
You can try using below apps:
https://splunkbase.splunk.com/app/1567/
https://splunkbase.splunk.com/app/3154/#/details
Also you can manually extract data using regex.
So I was expecting the default time input from Splunk_TA_nix to have extractions and tags that work with SplunkES. Was I mistaken?
Where did you installed add-on?
do you have the TA installed on the Search Head as well?