Splunk ver : 6.6.6
OS : Linux 7
Universal Forwarder ver : 6.6.6
OS : Windows Server 2016
I configured below inputs.conf and sample.ps1 in the Universal Forwarder and Splunk indexed once, but after that, no more events were indexed.
script = . "$SplunkHome\etc\apps\sample_app\bin\sample.ps1"
interval = */1 * * * *
sourcetype = power_shell_sapmle
$Output = invoke-expression "wmic cpu list brief"
Is my configuration wrong?
Please someone help me.
As per the docs, default the script executes only once.
To schedule the script, you can try using parameter
Let me know if this helps!!
View solution in original post
Thank you for answer!
I did not check the manual properly ...
It was very helpful.