All Apps and Add-ons

Splunk app for infrastructure can not show entities

nanachu
Path Finder

Hi all.

Thank you for helping me.

entities did not show up.
I use SUSE Linux Enterprise Server 12 SP4.

Where should I check to solve this problem?

I check index=_internal and my uf can connect.
I did this command in UF

./splunk list forward-server

And this returned.

Active forwards:
        ×.×.×.×:9997
Configured but inactive forwards:
        None

I think collectd is running.
I did this command.

service collectd status



 Active: active (running) since Tue 2020-01-21 08:10:37 UTC; 6s ago
     Docs: man:collectd(1)
           man:collectd.conf(5)
 Main PID: 4924 (collectd)
    Tasks: 11 (limit: 512)
   Memory: 2.4M
      CPU: 10ms
   CGroup: /system.slice/collectd.service
           └─4924 /usr/sbin/collectd

Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: [2020-01-21 08:10:37] plugin_load: plugin "df" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: plugin_load: plugin "load" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: [2020-01-21 08:10:37] plugin_load: plugin "load" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: plugin_load: plugin "disk" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: [2020-01-21 08:10:37] plugin_load: plugin "disk" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: plugin_load: plugin "interface" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: [2020-01-21 08:10:37] plugin_load: plugin "interface" successfully loaded.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: Systemd detected, trying to signal readyness.
Jan 21 08:10:37 iip-*.*.*.* systemd[1]: Started Collectd statistics daemon.
Jan 21 08:10:37 ip-*.*.*.* collectd[4924]: Initialization complete, entering read-loop.

Why my SAI can not show entities?
When I set up in Windows, entities shows up.

0 Karma
1 Solution

dagarwal_splunk
Splunk Employee
Splunk Employee

Putting it as answers:
https://answers.splunk.com/answers/793712/entities-not-displayed-in-splunk-app-for-infrastru.html#an...

NOTE: you will use zypper instead of apt for SUSE in some of the steps and some of the paths might be little different for SUSE ( collectd.conf /etc/collectd.conf).

View solution in original post

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Putting it as answers:
https://answers.splunk.com/answers/793712/entities-not-displayed-in-splunk-app-for-infrastru.html#an...

NOTE: you will use zypper instead of apt for SUSE in some of the steps and some of the paths might be little different for SUSE ( collectd.conf /etc/collectd.conf).

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Can you try following the 8 steps mentioned (2nd answer) here for debugging:
https://answers.splunk.com/answers/793712/entities-not-displayed-in-splunk-app-for-infrastru.html#an...

NOTE: you will use zypper instead of apt for SUSE in some of the steps and some of the paths might be little different for SUSE ( collectd.conf /etc/collectd.conf).

0 Karma

nanachu
Path Finder

Thank you so much!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...