Deployment Architecture

Why does Splunk only run my PowerShell script once after reloading the deployment server?

wstefanczyk
Engager

I'm a new Splunk user.

I created a new Powershell script and i don't know why Splunk runs it only once after reloading the Deployment Server

My input file:

[powershell://dq]
script = . "$SplunkHome\etc\apps\wins_inputs\local\dq.ps1"
source = dq
sourcetype = Powershell:dq
interval = 10
index = powershell

Powershell script:
dq.ps1

$computer         = $ENV:Computername
$instance         = "_total"

@("\\$Computer\PhysicalDisk(*)\Current Disk Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Read Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Write Queue Length") |% {
    (Get-Counter $_.replace("*",$instance)).CounterSamples } |
    Select-Object Path,CookedValue

Do you have any ideas why?

0 Karma
1 Solution

wstefanczyk
Engager

I found resolutions

i used schedule not interval

View solution in original post

0 Karma

wstefanczyk
Engager

I found resolutions

i used schedule not interval

0 Karma

SudarshanChakra
Loves-to-Learn

Hi 

I have tried using both interval and schedule but the script only runs on splunk restart or after reloading the deployment server. Any suggestions ? 

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...