Getting Data In

Scripted data input producing output not appearing in Splunk

EricLloyd79
Builder

I am completely baffled on why some of the output I am producing from a script (its key-value pairs) is not appearing in Splunk.
I have a Python script producing 4 key-value pairs:
kv1=123
kv2=234
kv3=445
kv4=233

kv3 and kv4 are not appearing but kv1 and kv2 are appearing. I tried using /opt/splunk/bin/python script.py to test if its producing the output and all the kv pairs are there but having it installed in Splunk data inputs, I am not seeing the last two.

Oddly enough, I have an identical script on another machine that queries a different host for metrics and it is producing all 4 kv pairs.

Anyone have any ideas?

0 Karma

EricLloyd79
Builder

The illogical mystery deepens. Apparently the actual value for kv1 and kv2 goes to splunk but the value for kv3 and kv4 doesn't. If I put the kv1 and kv2 values in the kv pair of kv3 and kv4, it works, so its not the key part, its the value itself.. All of the values are integers. All of the values print when the script is manually run. It like Splunk doesn't like v3 and v4 for some reason.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...