<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580635#M11112</link>
    <description>&lt;P&gt;You should try to run this script as user which are running UF client. Also try it with splunk cmd …../path/to/script. Then if/when needed fix reported errors.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jan 2022 15:56:11 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-01-11T15:56:11Z</dc:date>
    <item>
      <title>Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580630#M11109</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am not getting events from the uptime.sh which gives system date and uptime information via the shell command. This script is a part of Splunk Add-On for Unix and Linux which is installed on the universal forwarder. I am getting data from other inputs like cpu.sh, vmstat.sh, df.sh etc...but not only from uptime.sh. I check the disabled is also set to false and in sync with other stanzas like the stanzas of cpu,vmstat etc. Any insights into if I am missing anything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580630#M11109</guid>
      <dc:creator>mayankrojo</dc:creator>
      <dc:date>2022-01-11T15:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580631#M11110</link>
      <description>&lt;P&gt;Check the bin folder see if there any scripts which have different permissions than those of working ones.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:51:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580631#M11110</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-11T15:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580634#M11111</link>
      <description>&lt;P&gt;I checked with the permissions of the script in the default folder. It is exactly the same like others.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:54:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580634#M11111</guid>
      <dc:creator>mayankrojo</dc:creator>
      <dc:date>2022-01-11T15:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580635#M11112</link>
      <description>&lt;P&gt;You should try to run this script as user which are running UF client. Also try it with splunk cmd …../path/to/script. Then if/when needed fix reported errors.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580635#M11112</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-11T15:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580641#M11113</link>
      <description>&lt;P&gt;I am getting the data when i run the uptime.sh script from command line. But I am not getting the data in Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 16:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580641#M11113</guid>
      <dc:creator>mayankrojo</dc:creator>
      <dc:date>2022-01-11T16:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting events from sourcetype Unix:Uptime from Splunk Add-On from unix and linux (uptime.sh)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580748#M11128</link>
      <description>&lt;P&gt;If you are run it with "splunk" user and with command&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunkforward/splunk/bin/splunk cmd /path/to/script/uptime.sh&lt;/LI-CODE&gt;&lt;P&gt;And get answer then it should works.&lt;/P&gt;&lt;P&gt;Have you gotten anything into _internal logs on that client? Check also local log files under ..../splunk/var/log/splunk&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 09:51:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Not-getting-events-from-sourcetype-Unix-Uptime-from-Splunk-Add/m-p/580748#M11128</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-12T09:51:07Z</dc:date>
    </item>
  </channel>
</rss>

