All Apps and Add-ons

Splunk_TA_nix on EC2 Instances

sloshburch
Splunk Employee
Splunk Employee

While playing with EC2 instances, I have the Splunk_TA_nix app deployed. The cpu.sh returns nothing because sar and mpstat are not found on the EC2 host.

I understand that Linux has other ways to pull in system metrics, but things are obviously simpler if the same Splunk_TA_nix could be used everywhere I have *nix.

Anyone solve this quirk?

0 Karma
1 Solution

wvonalt_splunk
Splunk Employee
Splunk Employee

@Burch - you've already hit the nail on the head... just install the war package on the system and the problem is solved.

View solution in original post

wvonalt_splunk
Splunk Employee
Splunk Employee

@Burch - you've already hit the nail on the head... just install the war package on the system and the problem is solved.

sloshburch
Splunk Employee
Splunk Employee

Oh, so manually install sar or mpstat? I was hoping we were just missing some other cpu command from our cpu.sh script 😞

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Building off my own sillyness and expanding on @wvonalt answer:

Looks like it's as simple as yum install sysstat

0 Karma

sloshburch
Splunk Employee
Splunk Employee

My peers also hooked me up with this link, good to share here: http://docs.splunk.com/Documentation/UnixAddOn/latest/User/Whatdataarecollected

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...