Getting Data In

Powershell scripts giving blank / no outputs



I have observed a strange issue in few of my universal forwarders. This is with Splunk addon for windows. 

I have created scripts to check the disk and memory usage of the server and sent it back to Splunk. This setup is very old and working on majority of the servers. These inputs are scheduled to run every 5 min and 30 min respectively. 

Whenever I reload serverclass from my deployment server I can see 1 or 2 events coming in after that no data for either of the inputs. 

When I check the internal logs I can see that the script is being executed successfully but no output/event can be seen in Splunk search. 

I have tried direct execution of script in the input(writing the script in input stanza ) and saving in a path and calling from there as well. 

Note - I have even tried creating a separate app and deploying from there for these 2 specific inputs but the behavior is same. 

Can you please help me understand what is wrong and why it is giving blank output? 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...