Splunk® IT Service Intelligence

Entity Integrations Manual

Splunk IT Service Intelligence (ITSI) version 4.12.x reached its End of Life on January 22, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.

About Unix and Linux entity integration in ITSI

When you collect *nix data through the Unix and Linux entity integration in (ITSI), your entities are created by discovery searches and are automatically associated with entity types. You also gain access to prebuilt dashboards for each associated entity type. The following sections walk through the two ways you can add *nix data to ITSI through the Unix and Linux entity integrations. For information about data you can collect using this integration, see *nix data you can collect with ITSI.

Collect *nix data with the Splunk Add-on for Unix and Linux

The Splunk Add-on for Unix and Linux collects both metrics and logs data. Entities created through the Splunk Add-on for Unix and Linux integration have the entity type Unix/Linux Add-on To use this integration you need to install and configure the Splunk Add-on for Unix and Linux and the Splunk universal forwarder. When you collect *nix data with the add-on, you don't run the easy install script. For more information, see Collect *nix data in ITSI with the Splunk Add-on for Unix and Linux.

Collect *nix data with collectd and Splunk universal forwarder

There are two ways to collect *nix data with collectd and Splunk universal forwarder. Entities collected through collectd have entity type *nix.

Option one: Add data to ITSI with the collectd easy install script

When you run the *nix collectd easy install script, the universal forwarder and collectd are automatically installed on your machine. You can collect logs in addition to the metrics in the easy install script. For more information, see Collect *nix metrics and logs with the data collection script in ITSI.

Option two: Manually install and configure collectd and Splunk universal forwarder

You can manually set up collectd to collect metrics from a *nix host and collect log data for *nix systems with a universal forwarder. Manually configure metrics collection for a *nix host when you meet at least one of these conditions:

  • You're installing collectd on a closed network with no internet access.
  • You already installed collectd on the host.
  • You don't have trusted URLs that you can download the required packages and dependencies from.

If you want to collect metrics from a *nix host, see Manually collect metrics from a *nix host in ITSI. If you also want to collect log data from a *nix host, see Manually collect logs from a *nix host in ITSI.

Troubleshooting

If you have problems setting up the Unix and Linux entity integration, see Troubleshoot the Unix and Linux entity integration in ITSI.

Last modified on 28 April, 2023
Analyze entity performance metrics in ITSI   Unix and Linux integration requirements in ITSI for collectd

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.5, 4.11.6, 4.12.0 Cloud only, 4.12.1 Cloud only, 4.12.2 Cloud only, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.14.0 Cloud only, 4.14.1 Cloud only, 4.14.2 Cloud only, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.16.0 Cloud only, 4.17.0, 4.17.1, 4.18.0, 4.18.1, 4.19.0, 4.19.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters