Getting Data In

SA modular input powershell is directing data to default main indexer?

rjvydla
New Member

Hi All,
i tried using SA_modular_input_powershell app and i gave windows index in inputs.conf as index = windows.
when i didn't gave any index, the data is going to default main index. But when i gave index = windows or something the data is not getting generated.
what might be the reason.

ex:
[powershell://DriverInfo]
script = . "C:/Program Files/SplunkUniversalForwarder/etc/apps/SA-ModularInput-PowerShell/bin/DriverVersion.ps1"
interval = 14400

index = windows
sourcetype = Powershell

Thank you.

0 Karma

xpac
SplunkTrust
SplunkTrust

Most likely reason - the index you entered hasn't been created before.

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

0 Karma

rjvydla
New Member

i have been using the index i gave for other normal apps. it was woriking there but not in this app.

0 Karma
Get Updates on the Splunk Community!

Manual Instrumentation with Splunk Observability Cloud: The What and Why

If you've ever worked with distributed systems, you’ve likely felt the pain of a frontend throwing errors, ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...