Thanks For Downloading!
Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:
Unix/Linux: Decompress the downloaded file using a tool like
The Splunk on Splunk Technology Add-on is a collection of inputs for the Splunk on Splunk (SoS) app - http://www.splunk.com/goto/sos
Important: You do not need to install the S.o.S technology add-on on a Splunk instance where the S.o.S app is already installed. The S.o.S app ships with the same data inputs.
What is this add-on for, then?
This S.o.S technology add-on allows you to pull in resource usage data from remote Splunk instances running on Linux or Unix for display in your existing instance of the Splunk on Splunk app. To enable this, install and configure this S.o.S technology add-on on Linux and Unix search-peers or forwarders to track the resource usage of Splunk.
NOTE: You must enable the data inputs included in this add-on before they can report resource usage information. By default, these inputs are disabled. Refer to the README file for more information.
For more details on how to set up S.o.S and its technology add-on to monitor Splunk's system resource usage, please refer to the following Splunk Answers:
Versions and Release Notes
Version 2.0.4 (current version - updated May 06, 2013)
Bugs Fixed in version 2.0.4
* [SUP-672] Added an index definition for 'sos_summary_daily index' to indexes.conf.
* [SUP-627] Fixed an issue where the ps_sos.sh scripted input would no longer print out full process arguments when executed by Splunk 5.x on Solaris.
* [SUP-573] A new scripted input is now available to monitor the I/O usage of pooled search-heads on the shared NFS device: nfs-iostat_sos.py
* [SUP-541] Updated the app icon.
Version 2.0.3 (updated Dec 16, 2012)
Bugs fixed in version 2.0.3
* [SUP-617] Removed an undesirable carriage return in the app.conf description string.
* [SUP-568] Added an outputs.conf file with configuration that, if enabled, ensures that _internal events are forwarded.
* [SUP-558] Synched up lsof_sos.sh with the version shipping in the SoS app.
* [SUP-545] Adapted the ps_sos.sh scripted input to the new splunkd process command line format in 5.x.
Version 2.0.2 (updated Aug 24, 2012)
* [SUP-365] Added an app icon for the S.o.S TA for Unix and Linux.
Version 2.0.0 (updated Aug 24, 2012)
Version 2.0.1 (updated Dec 15, 2011)
Small changes to the README file.
there is a line break in the app.conf file:
[launcher] author = Splunk Support description = This is the technology add-on for the Splunk on Splunk app which provides custom inputs and indexes needed by to populate the app's views. This package of the S.o.S te chnology add-on is specific to Unix and Linux platforms.
which produces some messages during startup:
WARN IniFile - /opt/splunk/etc/apps/TA-sos/default/app.conf, line 15: Cannot parse into key-value pair: hnology add-on is specific to Unix and Linux platforms.
reviewed 30 Oct '12, 04:58
accept rate: 17%