Getting Data In

How to troubleshoot why a data input script inside an app is not running?

joao_amorim
Communicator

Hi

I have a script that I want to put inside the appName/bin dir inside a specific app.

Previously, the script was inside the splunkHome/bin and it works perfectly and in that app, I configured the inputs.conf and the default.meta accordingly to the script.

The problem is that when I moved the script from the splunkHome/bin dir to the appName/bin dir, I changed the inputs.conf and the default.meta again, but the script that previously gave me some results, now results don't appear.

I already saw this link:
http://docs.splunk.com/Documentation/Splunk/6.0.6/AdvancedDev/ScriptSetup

But it didn't help.

Anyone please.... Thanks

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi joao_amorim,

first, try to run the script manually in the new location:

 $SPLKUNK_HOME/bin/splunk cmd python $SPLUNK_HOME/etc/apps/YourAppName/bin/YourScript.py

assuming it's a python script.

If this shows no error but still does not work, add some logging functions to your script - see the docs for more details about this http://docs.splunk.com/Documentation/Splunk/6.4.0/AdvancedDev/ModInputsLog
Don't be confused that this link talks about modular inputs; the method of logging is the same for scripted or modular input.

Hope this helps ...

cheers, MuS

0 Karma

joao_amorim
Communicator

Ok i will try that.

Actually my script is a .ksh so i will try and then i will let you know.

Thanks

0 Karma

joao_amorim
Communicator

@MuS do you know how to run a .ksh script in splunk?? Because I don't figure it out and already tried a lot of possibilities but no luck at all.

Best regards

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...