I run Universal Forwarder 8.0.3 & Splunk Add-on for Unix and Linux 8.0.0 on AIX 7.1 while I found no event came to index = OS after I used ps -ef | grep splunk I found some script ex. Iostat.sh ,cpu.sh ... pending in the queue after we kill the jobs ex. Iostat.sh ,cpu.sh ... ,the event came to index and the schedule scripts were running agent . how can I trouble shooting the issue ????
The logs for Splunk Add-on for Unix and Linux are falling under the splunkd.log file. So, you can search the logs using the query "index=_internal sourcetype=splunkd ERROR NIX" with an appropriate timestamp for troubleshooting the issues in your environment.