<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scripted inputs fails on pooled search heads in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79376#M16277</link>
    <description>&lt;P&gt;It looks as if you have placed your input script in your Search Head pools shared storage path  hence the error saying that the script must live within $SPLUNK_HOME , //Server01/prod/SplunkSharedConfig is not your $SPLUNK_HOME&lt;/P&gt;

&lt;P&gt;You will need to place the script where Splunk is installed ie: $SPLUNK_HOME/etc/apps/Splunk_CiscoIPS/bin/get_ips_feed.py&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:33:36 GMT</pubDate>
    <dc:creator>Damien_Dallimor</dc:creator>
    <dc:date>2020-09-28T12:33:36Z</dc:date>
    <item>
      <title>Scripted inputs fails on pooled search heads</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79375#M16276</link>
      <description>&lt;P&gt;I am trying to implement the Cisco IPS App on pooled search heads, but the scripted inputs are failing with the following error: Incorrect path to script: \\Server01\prod\SplunkSharedConfig\etc\apps\Splunk_CiscoIPS\bin\get_ips_feed.py.  Script must be in a bin subdirectory in $SPLUNK_HOME.&lt;/P&gt;

&lt;P&gt;I've tested the path and it is correct.    Anyone have any thoughts?  &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79375#M16276</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2020-09-28T12:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted inputs fails on pooled search heads</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79376#M16277</link>
      <description>&lt;P&gt;It looks as if you have placed your input script in your Search Head pools shared storage path  hence the error saying that the script must live within $SPLUNK_HOME , //Server01/prod/SplunkSharedConfig is not your $SPLUNK_HOME&lt;/P&gt;

&lt;P&gt;You will need to place the script where Splunk is installed ie: $SPLUNK_HOME/etc/apps/Splunk_CiscoIPS/bin/get_ips_feed.py&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79376#M16277</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2020-09-28T12:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted inputs fails on pooled search heads</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79377#M16278</link>
      <description>&lt;P&gt;Makes sense.. but apps in searchhead pools aren't really shared if they are installed locally..&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 21:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79377#M16278</guid>
      <dc:creator>richnavis</dc:creator>
      <dc:date>2012-10-05T21:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted inputs fails on pooled search heads</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79378#M16279</link>
      <description>&lt;P&gt;You still have the apps shared via shared storage , but what you are doing in a distributed setup is splitting out the various components of the app.In this case you are splitting out the data collection components(get_ips_feed.py), which could possibly live on a Splunk forwarder or indexer,  from the data viewing and searching components(views, alerts, saved searches,eventtypes, lookups &amp;amp; various other knowledge objects) which can live on your search head pools shared storage path.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Scripted-inputs-fails-on-pooled-search-heads/m-p/79378#M16279</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2020-09-28T12:34:49Z</dc:date>
    </item>
  </channel>
</rss>

