Install the Splunk App for Unix and Linux
This topic guides you through the steps required to install the Splunk App for Unix and Linux.
The installation package for the Splunk App for Unix and Linux contains:
- Dashboards, reports, alerts, lookups, and macros for use with Splunk Web.
The Splunk Add-on for Unix and Linux (Splunk_TA_Nix
) is available as a separate download from Splunkbase. It is no longer part of the Splunk App for Unix and Linux package.
You can install the Splunk App for Unix and Linux package using Splunk Web or from the command line on a full Splunk instance only. You cannot install the app onto a universal forwarder as you must have Splunk Web to use the app.
Install the Splunk App for Unix and Linux from within Splunk Web
To install the Splunk App for Unix and Linux from within Splunk Web:
- Log into Splunk on the system on which you want to install the Splunk App for Unix and Linux. Splunk loads the Home screen.
- In the "Home" screen, click Find More Apps in the lower left-hand corner of the screen. Splunk loads the Browse more apps screen.
- In the "Browse more apps" screen, locate the Splunk App for Unix and Linux in the list, or type in "Splunk App for Unix and Linux" in the search box at the upper right hand corner of the screen.
- In the "Splunk App for Unix and Linux" entry in the list, click the Install Free button. Splunk installs the Splunk App for Unix and Linux, as well as the Splunk Add-on and Supporting Add-on for Unix and Linux.
- Restart Splunk to complete the app installation.
- Proceed to the "Log in and get started" page to continue using the app.
Install the Splunk App for Unix and Linux in Splunk Web from a downloaded file
Alternatively, you can download the Splunk App for Unix and Linux package and install it using Splunk Web:
- Download the Splunk app for Unix and Linux from Splunk Apps and save it to an accessible location.
Note: The file downloads with a
.tar.gz
extension. Do not attempt to run this file. - Log into Splunk on the system which you want to install the Splunk App for Unix and Linux.
- In the Home screen, click Manage Apps. Splunk loads the "Apps" screen.
- Click Install App from file. Splunk loads the Upload app screen.
- Click the Choose file button to locate the installation package you just downloaded.
- Click Upload. Splunk installs the Splunk App for Unix and Linux, as well as the Splunk Add-on and Supporting Add-on for Unix and Linux.
- Restart Splunk to complete the app installation.
- Proceed to the "Log in and get started" page to continue using the app.
Install the Splunk App for Unix and Linux from the command line
To install the Splunk App for Unix and Linux from the command line:
- Download the Splunk app for Unix and Linux from Splunk Apps, if you haven't already.
Note: The file downloads with a
.tar.gz
extension. Do not attempt to run this file. - Unpack the file into an accessible location.
- Copy the
splunk_app_for_nix
directory to$SPLUNK_HOME/etc/apps
. - Restart Splunk to complete the app installation.
- Proceed to the "Log in and get started" page to continue using the app.
Upgrade the Splunk App for Unix and Linux from previous versions
The SA-nix file is not included in versions 5.2.2 and later of the Splunk App for Unix and Linux. Manually delete SA-nix from your apps folder when upgrading from any version 5.2.1 and earlier.
To keep the categories and groups that you have configured,
- Copy the dropdowns.csv file in
etc/apps/SA-nix/lookups/
for a single instance deployment or$SPLUNK_HOME/etc/shcluster/apps
for a distributed deployment. - Move the dropdowns.csv file into
etc/apps/splunk_app_for_nix/lookups/
for a single instance deployment or$SPLUNK_HOME/etc/shcluster/apps
for a distributed deployment with your backup.
From version 5.0.x
You can upgrade directly from version 5.0 of the Splunk App for Unix and Linux through Splunk's in-app upgrade feature within Splunk Web, or from the command line.
From version 4.6.x and earlier
There is no supported upgrade path from version 4.6 of the Splunk App for Unix and Linux to this version. If you want, it is possible to run both version 4.6 and other versions simultaneously.
The installation package for this version of the app installs into a different directory than version 4.6. Once you have installed this version, you can then configure this version of the app to use the same indexes and source types that the version 4.6 app uses.
For detailed installation instructions, read "Install the Splunk App for Unix and Linux" in this manual.
Caution: Do not attempt to install this version of the app into the same directory of a version before 5.0. That is not supported and can render both versions of the app unusable.
Once you have configured and evaluated this version of the app, you can then remove the 4.6 version at a later date. No data loss will occur.
For information on any known issues in this version, review the release notes.
What a Splunk App for Unix and Linux deployment looks like | Install the Splunk Add-on for Unix and Linux |
This documentation applies to the following versions of Splunk® App for Unix and Linux (Legacy): 5.2.3, 5.2.4
Feedback submitted, thanks!