Getting Data In

Trouble with df.sh after upgrade to 9.2.1

dbagdanoff
Explorer

since moving to 9.2.1, now my df.sh events are now a single event when searching. also notice the format is bad when running the script compared to the built in df. novice linux guy here looking to see if anyone else has come across this. thanks!

splunk df

splunk df.png

 

 

linux df

linux df.PNG

 

 

 

 

splunk event

splunk event.PNG

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...