All Apps and Add-ons

Why doesn't my quartz scheduler cron settings used on Splunk Add-on for MS SCOM work?

hettervik
Builder

Hi folks,

I've installed a HF on a SCOM server to collect SCOM logs to Splunk. On the HF I've installed the Splunk Add-on for Microsoft System Center Operations Manager to collect logs using scheduled PowerShell scripts. The logs are indeed collected, but not on the interval I expected. One of my collection stanzas with the name "Events" uses the default quartz cron settings, which is 0 0 * ? * *. This should mean the the logs are collected every hour, but they are not, they are collected every midnight instead.

The add-on GUI on the HF for the collection stanza says 0 0 * ? * *, as well as the setting schedule in stanza [powershell://_Splunk_TA_micosoft_scominternal_used_Events] in inputs.conf, as well as the setting interval in stanza [Events] in microsoft_scom_task.conf. Yet the logs are only collected every midnight.

Anyone got an idea on why this is, or how I could go forward in troubleshooting this?

UPDATE: The version om SCOM we're running is 2012 r2 update 14.

1 Solution

hettervik
Builder

The problem solved itself when we upgraded the HF running the SCOM TA from Splunk Enterprise version 7.0.2 to version 7.1.2. Apparantly there was a bug (?) with the SCOM TA cron quartz scheduler on the old version.

View solution in original post

0 Karma

hettervik
Builder

The problem solved itself when we upgraded the HF running the SCOM TA from Splunk Enterprise version 7.0.2 to version 7.1.2. Apparantly there was a bug (?) with the SCOM TA cron quartz scheduler on the old version.

0 Karma

agupta2607
New Member

How did you resolve the issue?

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...