Getting Data In

SA-ModularInput-PowerShell problem.

mic1024
Path Finder

hi,
Im trying to use this app (as per tutorial from http://blogs.splunk.com/2013/06/24/monitoring-processes-on-windows/) however I'm running into a problem as per below:

05-28-2014 11:39:28.235 +0100 ERROR ModularInputs - Introspecting scheme=powershell: script running failed (exited with code 255).
05-28-2014 11:39:28.235 +0100 ERROR ModularInputs - Unable to initialize modular input "powershell"  defined inside the app "SA-ModularInput-PowerShell": Introspecting scheme=powershell: script running failed (exited with code 255).

My inputs.conf under C:\Program Files\SplunkUniversalForwarder\etc\apps\SA-ModularInput-PowerShell\local

[powershell://Processes]
script = Get-WmiObject -class win32_process | Add-Member -MemberType ScriptProperty -PassThru -Name Username -Value { $ud = $this.GetOwner();  $user=$ud.Domain+"\"+$ud.User;  if ($user -eq "\") { "SYSTEM" } else { $user } }|select ProcessId, Name, Username, Priority, ReadOperationCount, WriteOperationCount, CreationDate, Handle, VirtualSize, WorkingSetSize, UserModeTime, ThreadCount
schedule = 0,15,30,45 * * ? * *
source = PowerShell
sourcetype = PowerShell:Process

I've checked execution prolicy:

PS C:\Users\ireutildev> get-executionpolicy
RemoteSigned

version:

c:\Program Files\SplunkUniversalForwarder\bin>splunk version
Splunk Universal Forwarder 6.1.1 (build 207789)

Any ideas?
Thanks,
mic.

Tags (1)
0 Karma
1 Solution

mic1024
Path Finder

I've restarted the host and now it is working... so... yeah.. that... 😉

View solution in original post

mic1024
Path Finder

I've restarted the host and now it is working... so... yeah.. that... 😉

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...