Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Why is the Universal Forwarder not loading Splunk Add-on for Unix and Linux?

$
0
0
I'm working on deploying the Splunk Add-On for Unix and Linux to the universal forwarders in my environment using a configuration management system. I packaged the add-on into an RPM for easier management, which simply decompresses the archive into `$SPLUNK_HOME/etc/apps` so that I now have `/opt/splunkforwarder/etc/apps/Splunk_TA_nix` with the application - directories `appserver`, `bin`, etc. I've created a `local` directory and copied `default/inputs.conf` into it with inputs and enabled a number of the inputs. However, the single-node Splunk server, which does receive a number of other inputs from this forwarder, is not getting any of the inputs configured in the app. I've examined the output from splunkd, and during startup it lists that it is reading in the various configuration stanzas in `/opt/splunkforwarder/system/local/inputs.conf`, but it does not output anything about any of the stanzas configured in the Splunk Add-on for Unix and Linux. This makes me think that it's completely ignoring the add-on, but I can't figure out why. I've checked and the add-on folder is owned by root but is all readable by Splunk. Any ideas as to why it's not working?

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>