<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scripted Inputs not functioning in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-Inputs-not-functioning/m-p/505266#M86097</link>
    <description>&lt;P&gt;I've configured three bash scripts, all of which do essentially the same exact thing.&lt;/P&gt;&lt;P&gt;1. Run a command and send the output to a file&lt;/P&gt;&lt;P&gt;2. Parse this file via a Python script (Which then prints the parsed file to the console, sending it to Splunk)&lt;/P&gt;&lt;P&gt;3. Delete the file&lt;/P&gt;&lt;P&gt;Two of the three scripts work exactly as intended, with no issues whatsoever. The third, however, sends no information to Splunk at all. I can run the python portion independently, the bash script w/ the python script, and both can, additionally, be done through'/opt/splunkforwarder/bin/splunk cmd', and, in all instances, it provides the desired output to the cmd line without it being ingested.&lt;/P&gt;&lt;P&gt;If I alter the script and purposefully put in errors they will appear in the _internal index. Aside from that, nothing related to issues with the script appears there.&lt;/P&gt;&lt;P&gt;All of the scripts are set up in the exact same manner in the inputs.conf file, with them all using the same source-type and index.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance on how to proceed with the troubleshooting would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 19:42:55 GMT</pubDate>
    <dc:creator>KyleH</dc:creator>
    <dc:date>2020-06-19T19:42:55Z</dc:date>
    <item>
      <title>Scripted Inputs not functioning</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-Inputs-not-functioning/m-p/505266#M86097</link>
      <description>&lt;P&gt;I've configured three bash scripts, all of which do essentially the same exact thing.&lt;/P&gt;&lt;P&gt;1. Run a command and send the output to a file&lt;/P&gt;&lt;P&gt;2. Parse this file via a Python script (Which then prints the parsed file to the console, sending it to Splunk)&lt;/P&gt;&lt;P&gt;3. Delete the file&lt;/P&gt;&lt;P&gt;Two of the three scripts work exactly as intended, with no issues whatsoever. The third, however, sends no information to Splunk at all. I can run the python portion independently, the bash script w/ the python script, and both can, additionally, be done through'/opt/splunkforwarder/bin/splunk cmd', and, in all instances, it provides the desired output to the cmd line without it being ingested.&lt;/P&gt;&lt;P&gt;If I alter the script and purposefully put in errors they will appear in the _internal index. Aside from that, nothing related to issues with the script appears there.&lt;/P&gt;&lt;P&gt;All of the scripts are set up in the exact same manner in the inputs.conf file, with them all using the same source-type and index.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance on how to proceed with the troubleshooting would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 19:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Scripted-Inputs-not-functioning/m-p/505266#M86097</guid>
      <dc:creator>KyleH</dc:creator>
      <dc:date>2020-06-19T19:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted Inputs not functioning</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Scripted-Inputs-not-functioning/m-p/505315#M86101</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222751"&gt;@KyleH&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first you don't need to write the script results in a file, but you can directly send script output to Splunk (as you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.4/AdvancedDev/ScriptedInputsIntro" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.4/AdvancedDev/ScriptedInputsIntro&lt;/A&gt;&amp;nbsp;).&lt;/P&gt;&lt;P&gt;Then the only hint I can give you is to test the script by itself:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;does it give results or not?&lt;/LI&gt;&lt;LI&gt;has the user you're using for Splunk the grants to execute that script and access the files?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2020 06:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Scripted-Inputs-not-functioning/m-p/505315#M86101</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-20T06:30:27Z</dc:date>
    </item>
  </channel>
</rss>

