<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Scripted Inputs ingesting only Headers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533093#M89564</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Splunk is ingesting only a portion of the scripted input ps.sh from my *nix os TA, and I don't know why.&lt;/P&gt;&lt;P&gt;Before a certain date, it was all ingesting fine. After a particular date, it's begun to only ingest the Headers from the script output, rather than the output values themselves:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;USER               PID   PSR   pctCPU       CPUTIME  pctMEM     RSZ_KB     VSZ_KB   TTY      S       ELAPSED  COMMAND             ARGS&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced this before?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2020 05:12:21 GMT</pubDate>
    <dc:creator>rmccullagh</dc:creator>
    <dc:date>2020-12-15T05:12:21Z</dc:date>
    <item>
      <title>Splunk Scripted Inputs ingesting only Headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533093#M89564</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Splunk is ingesting only a portion of the scripted input ps.sh from my *nix os TA, and I don't know why.&lt;/P&gt;&lt;P&gt;Before a certain date, it was all ingesting fine. After a particular date, it's begun to only ingest the Headers from the script output, rather than the output values themselves:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;USER               PID   PSR   pctCPU       CPUTIME  pctMEM     RSZ_KB     VSZ_KB   TTY      S       ELAPSED  COMMAND             ARGS&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced this before?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 05:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533093#M89564</guid>
      <dc:creator>rmccullagh</dc:creator>
      <dc:date>2020-12-15T05:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Scripted Inputs ingesting only Headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533269#M89576</link>
      <description>&lt;P&gt;This is for "Splunk Add-on for Unix and Linux" version 8.0.0&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 05:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533269#M89576</guid>
      <dc:creator>rmccullagh</dc:creator>
      <dc:date>2020-12-16T05:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Scripted Inputs ingesting only Headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533295#M89578</link>
      <description>&lt;P&gt;Run the script directly in the server and check whether we are getting the output properly. If you are getting an output save to a temp file and check how it is appearing. Each line needs to have separate process details.&lt;/P&gt;&lt;P&gt;sh ps.sh &amp;gt; temp.txt&lt;/P&gt;&lt;P&gt;cat -n temp.txt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 08:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533295#M89578</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2020-12-16T08:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Scripted Inputs ingesting only Headers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533524#M89604</link>
      <description>&lt;P&gt;Thanks, did this and it led me to investigate props.conf on HF's that was having issues.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 00:37:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Scripted-Inputs-ingesting-only-Headers/m-p/533524#M89604</guid>
      <dc:creator>rmccullagh</dc:creator>
      <dc:date>2020-12-18T00:37:32Z</dc:date>
    </item>
  </channel>
</rss>

