Splunk® App for Unix and Linux (Legacy)

Install and Use the Splunk App for Unix and Linux

Acrobat logo Download manual as PDF


On March 13, 2022, the Splunk App for Unix and Linux will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app has migrated to a content pack in Data Integrations. Learn about the Content Pack for Unix Dashboards and Reports.The Splunk Add-on for Unix and Linux remains supported.
This documentation does not apply to the most recent version of Splunk® App for Unix and Linux (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Enable data and scripted inputs

Once you have installed the Splunk App for Unix and Linux, you must enable the data and scripted inputs within the Splunk Add-on for Unix and Linux (Splunk_TA_nix) in order for the add-on to collect data and send it to the indexers in the central Splunk App for Unix and Linux instance.

To enable the inputs included with the Splunk Add-on for Unix and Linux:

1. Make a copy of $SPLUNK_HOME/etc/apps/Splunk_TA_nix/default/inputs.conf and place it into $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local.

Note: If the $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local directory does not exist, you will need to create it.

2. Open $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local/inputs.conf for editing.

Caution: Do not edit the inputs.conf file in $SPLUNK_HOME/etc/apps/Splunk_TA_nix/default. This file gets overwritten whenever you upgrade the app.

3. Enable the inputs that you want the app to monitor by setting the disabled attribute for each input stanza to 0.

4. Save the file.

5. Restart your Splunk instance:

# ./splunk restart
Last modified on 14 November, 2013
PREVIOUS
Install the Splunk App for Unix and Linux in a distributed Splunk environment
  NEXT
Log in and get started

This documentation applies to the following versions of Splunk® App for Unix and Linux (Legacy): 5.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters