All Apps and Add-ons

SoS - Debian Install - Not showing any CPU results

ukpbz
Explorer

Hi

I am running SoS on a Debian install. I have systat loaded but when I try and view cpu/memory util, I get the no results 'inspect' show

Any ideas?

Thanks

1 Solution

hexx
Splunk Employee
Splunk Employee

You need to enable the 'ps_sos.sh' scripted input for that view to populate. Take a look at this Splunk Answer for details on how to do this.

View solution in original post

hexx
Splunk Employee
Splunk Employee

You need to enable the 'ps_sos.sh' scripted input for that view to populate. Take a look at this Splunk Answer for details on how to do this.

hexx
Splunk Employee
Splunk Employee

Issues with 'lsof_sos.sh' have been reported lately, but we haven't had the opportunity to dig deeper into them or reproduce the problem in-house yet. You may want to look up that Splunk Answer I just linked and use the work-around provided if you find out that manually running $SPLUNK_HOME/bin/splunk cmd $SPLUNK_HOME/etc/apps/sos/bin/lsof_sos.sh yields no output.

0 Karma

ukpbz
Explorer

Actually that still didn't fix the file descriptor usage view 😞

0 Karma

ukpbz
Explorer

Many thanks.....

Now you have mentioned it, when I click Sos -> Resource Usage -> File Descriptor Usage - it falshes up a screen for a second and I saw that file name lsof_sos.sh in bold but didn't have time to read the text around it before the usage page loaded.

I enabled all the scripts in the manager for sos in the end

Thanks

hexx
Splunk Employee
Splunk Employee

For file descriptor usage, you need to enable 'lsof_sos.sh'. You'll find these requirements explained in the README file of the app or in the "Learn More" panel of the respective views. We always point out post-installation actions needed to enable a view in that panel 🙂

0 Karma

ukpbz
Explorer

Many Thanks, That worked.

Is there a list of what scripts need enabling as the same thing happens with file descriptor usage

Thanks

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...