Getting Data In

Why can't Splunk continuously index data from a powershell input?

yutaka1005
Builder

Splunk ver : 6.6.6
OS : Linux 7

Universal Forwarder ver : 6.6.6
OS : Windows Server 2016

I configured below inputs.conf and sample.ps1 in the Universal Forwarder and Splunk indexed once, but after that, no more events were indexed.

inputs.conf

[powershell://power_shell_sapmle]
script = . "$SplunkHome\etc\apps\sample_app\bin\sample.ps1"
interval = */1 * * * *
sourcetype = power_shell_sapmle

sample.ps1

$Output = invoke-expression "wmic cpu list brief"
Write-Output $Output

Is my configuration wrong?

Please someone help me.

0 Karma
1 Solution

deepashri_123
Motivator

Hey@yutaka1005,

As per the docs, default the script executes only once.
To schedule the script, you can try using parameter

schedule=<cron>

https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorWindowsdatawithPowerShellscripts

Let me know if this helps!!

View solution in original post

deepashri_123
Motivator

Hey@yutaka1005,

As per the docs, default the script executes only once.
To schedule the script, you can try using parameter

schedule=<cron>

https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorWindowsdatawithPowerShellscripts

Let me know if this helps!!

yutaka1005
Builder

Thank you for answer!

I did not check the manual properly ...
It was very helpful.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...