I am trying to following the instructions on the nmon performance monitor splunk app for unix and linux documentation (I don't have enough karma points to post the link, apparently, so the below link may not show):
https://nmon-for-splunk.readthedocs.io/en/latest/installation_splunkcloud.html
Anyway, I am on the "Deploy to Splunk Cloud" page in the documentation, looking at the deployment matrix. I have:
Name: NMON Performance by Octamis
Folder: nmon
Version: 1.9.19
Self-service installed on Splunk Cloud with install location of Search Heads and Indexers (I did not specify the location, it just installed there).
Name: PA-nmon_light
Folder: PA-nmon_light
Version: 1.3.22
Self-service installed on Splunk Cloud with install location of Search Heads and Indexers.
Name: Splunk_TA_nmon deployed to a linux box via the deployment server.
I have a custom inputs.conf defined on that same host in a local directory that has this:
[monitor:///var/nmon_repo/]
disabled = false
whitelist = \.nmon$
index = nmon
sourcetype = nmon_processing
crcSalt =
(stolen mostly from the "Indexing Nmon data generated out of Splunk" section on the page after "Deploy to Splunk Cloud")
Finally, I created the nmon index in Splunk Cloud. I do have data going into Splunk Cloud, but that data just looks like raw text and is not being parsed in the ways that it apparently needs to be in order for the NMON app dashboards to work as expected.
I did not configure nmon on the server (another developer did that) - is there some special way that has to be done in order for all of this to work? Am I missing some step to generate data models or something like that?
I know that Guilhem Marchand visits these forums and answers a lot of NMON questions, so hopefully this question will attract his attention! Of course, I am happy to receive help from anyone else who has gotten this working for Splunk Cloud!
Thanks, Splunkers!
... View more