<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154990#M14097</link>
    <description>&lt;P&gt;I get 0 results for anything with index=mssql --- that's what I don't understand&lt;/P&gt;</description>
    <pubDate>Wed, 08 Oct 2014 13:42:34 GMT</pubDate>
    <dc:creator>halkelley</dc:creator>
    <dc:date>2014-10-08T13:42:34Z</dc:date>
    <item>
      <title>Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154988#M14095</link>
      <description>&lt;P&gt;I've done the install and set the powershell execution policy to bypass, rebuilt the lookups, and I'm still not getting any SQL server data in Splunk&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 20:39:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154988#M14095</guid>
      <dc:creator>halkelley</dc:creator>
      <dc:date>2014-10-07T20:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154989#M14096</link>
      <description>&lt;P&gt;Take a look through the TA-sqlserver inputs.conf - each stanza has an index and a sourcetype.  A good search is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=mssql | chart count by host,sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will tell you which hosts are producing which sourcetypes.  Correlate that visually with the list of sourcetypes from your inspection of the inputs.conf file and you will know which pieces are not running.  Once you have that, the next step is to look for possible errors.  A search that will help there is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*powershell*.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Look for any obvious errors.  Anything leap out at you?  If nothing does, then take a look at the splunkd.log which you can use a similar search as above.&lt;/P&gt;

&lt;P&gt;Let me know what you find out.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2014 02:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154989#M14096</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2014-10-08T02:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154990#M14097</link>
      <description>&lt;P&gt;I get 0 results for anything with index=mssql --- that's what I don't understand&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2014 13:42:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154990#M14097</guid>
      <dc:creator>halkelley</dc:creator>
      <dc:date>2014-10-08T13:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154991#M14098</link>
      <description>&lt;P&gt;in the powershell log I see some maybe problematic events:&lt;/P&gt;

&lt;P&gt;...sourcetype = powershell-too_small...&lt;/P&gt;

&lt;P&gt;...Inner Exception PSSecurityException: File C:\Program Files\Splunk\etc\apps\SA-ModularInput-PowerShell\windows_x86_64\bin\Modules\LocalStorage\LocalStorage.psm1 cannot be loaded because running scripts is disabled on this system. For more information, see about_Execution_Policies at &lt;A href="http://go.microsoft.com/fwlink/?LinkID=135170" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkID=135170&lt;/A&gt;...&lt;/P&gt;

&lt;P&gt;in the splunkd logs I see a bunch of "GET"s and "POST"s, but nothing seems to be erroring&lt;/P&gt;

&lt;P&gt;thanks for your help!&lt;BR /&gt;
any ideas where to go from here?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:50:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154991#M14098</guid>
      <dc:creator>halkelley</dc:creator>
      <dc:date>2020-09-28T17:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154992#M14099</link>
      <description>&lt;P&gt;Follow-up answer.&lt;/P&gt;

&lt;P&gt;The Exception mentioned in your comment indicates that you have not enabled script execution properly.  Microsoft limits the scripts that can be run via PowerShell for security reasons.  The default setting is AllSigned, indicating that the scripts must have a digital signature.  We do not ship the scripts signed.  As a result, you need to ensure the proper execution policy is implemented.  In the short term, you can set the proper execution policy by running the following command from an ELEVATED PowerShell console:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Set-ExecutionPolicy RemoteSigned
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, a group policy may over-ride this setting, so ensure your group policy from Active Directory does not reset it for you.  If it does, then get the change made in Active Directory.  &lt;/P&gt;

&lt;P&gt;In addition, the system will not execute "blocked" scripts.  When you download a file from the internet, Windows blocks the execution of the file.  If you unpack the file without unblocking it, then all the unpacked files are similarly blocked.  You may need to go into the path mentioned in the log, right-click on the file, select Properties and unblock the file.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 15:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154992#M14099</guid>
      <dc:creator>ahall_splunk</dc:creator>
      <dc:date>2014-10-09T15:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154993#M14100</link>
      <description>&lt;P&gt;in following the directions, I previously set the execution policy to "bypass"...when I open a powershell window from ssms and "get-executionPolicy" it is "bypass"&lt;/P&gt;

&lt;P&gt;when does the powershell script attempt to execute?...can I repeat it?...the error I have in the powershell log is from 2 days ago, so it is possible I fixed it with the "bypass" setting?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 15:51:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154993#M14100</guid>
      <dc:creator>halkelley</dc:creator>
      <dc:date>2014-10-09T15:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154994#M14101</link>
      <description>&lt;P&gt;I figured out I wasn't running the powershell console in ELEVATED mode (run as Administrator) - thanks so much for your help!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 20:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/154994#M14101</guid>
      <dc:creator>halkelley</dc:creator>
      <dc:date>2014-10-09T20:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Microsoft SQL Server: Why am I not getting any SQL server data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/548714#M65433</link>
      <description>&lt;P&gt;That is so annoying, and super annoying that it isn't listed in the requirements section of the &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/MonitorWindowsdatawithPowerShellscripts" target="_blank" rel="noopener"&gt;Monitor Windows data with PowerShell scripts&lt;/A&gt; documentation. We aren't going to be changing our hundreds of servers security settings to enable one Splunk input. Unfortunately I only found this issue after wasting time making my powershell script and testing it locally before trying to run in a deployment-app. Many other programs which run powershell remotely (e.g. Octopus Deploy) can run the scripts remotely with the default Windows security settings for Powershell.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 04:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Microsoft-SQL-Server-Why-am-I-not-getting-any-SQL/m-p/548714#M65433</guid>
      <dc:creator>jeremyfer</dc:creator>
      <dc:date>2021-04-21T04:26:03Z</dc:date>
    </item>
  </channel>
</rss>

