Hi dpkar,
yes, you have to install the TA also on the Indexer, we missed that. Afterwards everthing works fine.
Just as hint, we found it very annoying that you can't filter which processes are really needed and you always have to index every single process. So we created another app which is filtering the really needed processes on the indexer and throw away any unneeded process information to keep down the license usage.
props.conf
[ps]
TRANSFORMS-psfilter = setnull,psfilter
[psfilter]
REGEX = .(process1|process2|process3 ....).
DEST_KEY = queue
FORMAT = indexQueue
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
and you have to add the following props within the Splunk_TA_nix
props.conf
[ps]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TRUNCATE=1000000
DATETIME_CONFIG = CURRENT
KV_MODE = none
PREAMBLE_REGEX = USER PID PSR pctCPU CPUTIME pctMEM RSZ_KB VSZ_KB TTY S ELAPSED COMMAND ARGS
EXTRACT-fields = (?\w+)\s+(?\d+)\s+(?[\w\?]+)\s+(?[\d.]+)\s+(?[\d.:-]+)\s+(?[\d.]+)\s+(?\d+)\s+(?\d+)\s+(?[\d\w\?\/]+)\s+(?\w+)\s+(?[\d:-]+)\s+(?[\w-.\d\/[]()]+)\s+(?.*)
Maybe thats usefull for you to
Best regards,
Alex
... View more