Getting Data In

Scripted data input producing output not appearing in Splunk

EricLloyd79
Builder

I am completely baffled on why some of the output I am producing from a script (its key-value pairs) is not appearing in Splunk.
I have a Python script producing 4 key-value pairs:
kv1=123
kv2=234
kv3=445
kv4=233

kv3 and kv4 are not appearing but kv1 and kv2 are appearing. I tried using /opt/splunk/bin/python script.py to test if its producing the output and all the kv pairs are there but having it installed in Splunk data inputs, I am not seeing the last two.

Oddly enough, I have an identical script on another machine that queries a different host for metrics and it is producing all 4 kv pairs.

Anyone have any ideas?

0 Karma

EricLloyd79
Builder

The illogical mystery deepens. Apparently the actual value for kv1 and kv2 goes to splunk but the value for kv3 and kv4 doesn't. If I put the kv1 and kv2 values in the kv pair of kv3 and kv4, it works, so its not the key part, its the value itself.. All of the values are integers. All of the values print when the script is manually run. It like Splunk doesn't like v3 and v4 for some reason.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...