Deployment Architecture

Why does Splunk only run my PowerShell script once after reloading the deployment server?


I'm a new Splunk user.

I created a new Powershell script and i don't know why Splunk runs it only once after reloading the Deployment Server

My input file:

script = . "$SplunkHome\etc\apps\wins_inputs\local\dq.ps1"
source = dq
sourcetype = Powershell:dq
interval = 10
index = powershell

Powershell script:

$computer         = $ENV:Computername
$instance         = "_total"

@("\\$Computer\PhysicalDisk(*)\Current Disk Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Read Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Write Queue Length") |% {
    (Get-Counter $_.replace("*",$instance)).CounterSamples } |
    Select-Object Path,CookedValue

Do you have any ideas why?

0 Karma
1 Solution


I found resolutions

i used schedule not interval

View solution in original post

0 Karma


I found resolutions

i used schedule not interval

0 Karma



I have tried using both interval and schedule but the script only runs on splunk restart or after reloading the deployment server. Any suggestions ? 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...