Getting Data In

Splunk Enterprise 7.0.1 not populating Events from SCOM 2007 R2 after installing Splunk Add on for Microsoft SCOM version 2.1.0

sameerchowdhary
New Member

I have installed product Splunk Enterprise 7.0.1 & downloaded it. I installed the product on Windows 7 machine & also downloaded the Add-On named Splunk Add on for Microsoft SCOM version 2.1.0 & installed it as well into Splunk.
I configured the inputs for SCOM in Splunk for Events it but it is not fetching any data / Events from SCOM 2007 R2.

Aslo the Powershell scripts for SCOM are not working, it is throwing errors given below

powershell.exe"" splunk-powershell - Powershell::LaunchPowershellHost: CreateProcess failed: 0x2
01-11-2018 20:32:29.543 +0530 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-powershell.exe"" splunk-powershell - Powershell::StartPowershellHost: Failed to start powershell host.

Can anybody who have installed the SCOM Addon help me in getting it configured.

Tags (1)
0 Karma

jmsbam
New Member

Just ran into this issue myself.  In my case we found a handful of UF's that had corrupted PATH statements.  Verify you have a correct system path by executing the following Powershell cmd-let

$env:path

If your path statement does not contain the following entries, chances are this is why you are receiving the .

C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\

 

0 Karma

Kelly
Loves-to-Learn

Was there a fix for this? I'm having the same Powershell errors. I've tried multiple 7 & 8 versions of Splunk UF.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...