Getting Data In

Powershell scripts giving blank / no outputs

SudarshanChakra
Loves-to-Learn

Hello, 

I have observed a strange issue in few of my universal forwarders. This is with Splunk addon for windows. 

I have created scripts to check the disk and memory usage of the server and sent it back to Splunk. This setup is very old and working on majority of the servers. These inputs are scheduled to run every 5 min and 30 min respectively. 

Whenever I reload serverclass from my deployment server I can see 1 or 2 events coming in after that no data for either of the inputs. 

When I check the internal logs I can see that the script is being executed successfully but no output/event can be seen in Splunk search. 

I have tried direct execution of script in the input(writing the script in input stanza ) and saving in a path and calling from there as well. 

Note - I have even tried creating a separate app and deploying from there for these 2 specific inputs but the behavior is same. 

Can you please help me understand what is wrong and why it is giving blank output? 

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...