Getting Data In

Powershell script input on a schedule

gavsdavs_GR
Path Finder

Not sure if this is a bug or just weird behaviour, I don't seem to be able to work around it.

I have loads of powershell windows inputs running on my UFs but they are running on UF restart as well as on their schedule(s).
{code}
[powershell://name]
script = & stuff
schedule = 0 23 15 * * *
source = PowerShell
sourcetype = PowerShell:Name
index = my index
interval =
{code}

I want this ONLY to run at 15:23.
What I am seeing is that if the UF is restarted, it's run on startup, AND it's run on the schedule i tell it.
i don't want it running on UF startup.

I believe i'm using the quartz notation and that bit is working as intended, but I don't want this input to be run if the UF is restarted.

Why is this happening ?

MayurSplunk
Explorer

Please share if the issue has been resolved in later releases.

0 Karma

MayurSplunk
Explorer

Any update on this ... has it been resolved by Splunk ?

0 Karma

meglin_splunk
Splunk Employee
Splunk Employee

I believe this is a known issue. Please raise a case with Splunk Support quoting SPL-141385.

psla
Explorer

Any update? This issue still persists in 9.1.x version (and I assume in 9.2.x also because there is no information in release notes/fixed issues). Now it's very difficult to control the execution of scripts.

[script://] input has this feature implemented, but [powershell://] don't.

* NOTE: when you specify a cron schedule, the input does not run the
  script on start-up.

 

0 Karma

adonio
Ultra Champion

its the default behavior to run scripted inputs on forwarder start, i am not sure however how (and why) to disable it

0 Karma

gavsdavs_GR
Path Finder

That isn't very desirable. If i supply a schedule, then that's when i want it to run, not whenever the UF is restarted.

0 Karma

cpaulraj
New Member

Has anyone figured out how to disable this behavior? We would like the powershell to run only at scheduled time not everytime the UF is started.

0 Karma

DanielPi
Moderator
Moderator

Hi @cpaulraj ,

I’m a Community Moderator in the Splunk Community.

This question was posted 7 years ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the  visibility it deserves. To increase your chances of getting help from the community, follow these guidelines in the Splunk Answers User Manual when creating your post.

Thank you! 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...