All Apps and Add-ons

I am not recieving anything in splunk app for unix and linux. what can i do to resolve it?

anshuman19
Explorer

I installed the Splunk add-on for unix and Linux on my Linux machine which have forwarder installed in it and installed splunk app for unix and Linux in windows which is the receiver but I am not receiving any thing in my splunk app, the setting in APP is as follows:
UNIX INDEX
index=main
index=os
SYSLOG DATA

sourcetype=syslog
CPU DATA
sourcetype=Linux_CPUTime
sourcetype=cpu
DF DATA
sourcetype=df
When I run setup.sh it ask username and password I enter my username and password and then a menu open which have certain options I choose
Manage *nix inputs
and then it again open menu
so I choose enable all inputs
but then it gives me error
"ENABLING FAILED"
I cant figure out what is the problem can anyone help me out.

0 Karma

p_gurav
Champion

Hi,

In below doc link, you can try "Enable the data and scripted inputs with configuration files" section.
http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Enabledataandscriptedinputs

Also did you restart splunk after enabling input?

0 Karma

anshuman19
Explorer

I already gone through the docs.
restart splunk enterprise or UF?
I installed Splunk add for unix on splunk enterprise also but it says:
This server is not running a known Unix or Linux operating system. Install this add-on on Unix or Linux systems only.

0 Karma

p_gurav
Champion

restart universal forwarder. Also what OS you have of the system where you indexing data from UF, is it windows?

0 Karma

anshuman19
Explorer

yes windows.

0 Karma

anshuman19
Explorer

restarted the universal forwarder but nothing received.

0 Karma

p_gurav
Champion

Check out this solution:

https://answers.splunk.com/answers/237809/why-am-i-getting-this-error-trying-to-configure-th.html

Also check internal log for any errors, and try searching index=os or index=main in Searching and reporting app.

Also you need to install ad-on on forwarder and search head both.

0 Karma

anshuman19
Explorer

How to install add-on on search head?
http://docs.splunk.com/Documentation/UnixAddOn/5.2.0/User/DeploytheSplunkAdd-onforUnixandLinuxinadis...
In above doc its mentioned that splunk app for unix to be installed on search head that I have already done.
but I want to confirm here that splunk enterprise is refered here as search head?

0 Karma

p_gurav
Champion

Please go through this doc to check where you need to install add-on and app:

https://docs.splunk.com/Documentation/UnixApp/5.2.3/User/DeploytheSplunkAppforUnixandLinuxinadistrib...

0 Karma

anshuman19
Explorer

ok so in my case I have splunk enterprise installed in windows which in my knowledge is both the indexed and search head and Splunk app for unix is also installed on splunk enterprise , and universal forwarder is installed in Ubuntu with splunk addon installed . My forwarder is working as I can see data coming in through Forwarders: Instance in default dashboard.
I have not defined any indexer in splunk enterprise, now coming to my Linux machine which have universal forwarder to install Splunk addon for unix I moved my unpacked downloaded files to $SPLUNK_HOME/etc/apps and restarted.
Now for enabling script and data input I used below command
$SPLUNK_HOME/bin/splunk cmd $SPLUNK_HOME/etc/apps/Splunk_TA_nix/bin/setup.sh
which directed me to the menu page and given me the enabling failed error as I mentioned above.
So this the whole thing I have done.I am not sure about the

1)Install the Splunk App for Unix and Linux on an indexer
2)Install the Splunk App for Unix and Linux on a search head
in http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/DeploytheSplunkAdd-onforUnixandLinuxinadis...
as I have only one forwarder so I don't think I have to do any thing for 1 and 2.
Now please tell me what is wrong and how t solve the issue.

0 Karma

p_gurav
Champion

Hi,

ok. Now install Splunk_TA_nix on your search head like you install unix app. Also can you check forwarder's internal logs. Also try to configure input using configuration files(inputs.conf in unix add-on on forwarder) instead setup.sh.

0 Karma

anshuman19
Explorer

I have doubt search head here is splunk enterprise right? Because I have only one forwarder.
I already installed it in my splunk enterprise( installed in windows )but it says "This server is not running a known Unix or Linux operating system. Install this add-on on Unix or Linux systems only. "

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...