Deployment Architecture

Why does Splunk only run my PowerShell script once after reloading the deployment server?


I'm a new Splunk user.

I created a new Powershell script and i don't know why Splunk runs it only once after reloading the Deployment Server

My input file:

script = . "$SplunkHome\etc\apps\wins_inputs\local\dq.ps1"
source = dq
sourcetype = Powershell:dq
interval = 10
index = powershell

Powershell script:

$computer         = $ENV:Computername
$instance         = "_total"

@("\\$Computer\PhysicalDisk(*)\Current Disk Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Read Queue Length",
  "\\$Computer\PhysicalDisk(*)\Avg. Disk Write Queue Length") |% {
    (Get-Counter $_.replace("*",$instance)).CounterSamples } |
    Select-Object Path,CookedValue

Do you have any ideas why?

0 Karma
1 Solution


I found resolutions

i used schedule not interval

View solution in original post

0 Karma


I found resolutions

i used schedule not interval

0 Karma



I have tried using both interval and schedule but the script only runs on splunk restart or after reloading the deployment server. Any suggestions ? 

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...