Getting Data In

Why doesn't Splunk Enterprise 8 display the results of a command (i.e. btool, etc.) on Windows 10 using SSH (putty)?

Nanuk
Explorer

Hi so I've been teaching myself Splunk and I don't really have the HDD space to run VM on my WIndows 10 desktop or laptop, and the thought to dual booting CentOS on both scares me since I don't have anywhere to backup my data atm.

I've actually looked for an answer to this here and on google and have not found an answer to this question. Some people have asked questions similar to this and the answer is usually to run an elevated command prompt as admin. This doesn't work for me.

I've installed Splunk Enterprise Trial 8 on my laptop and install the new WIndows 10 OpenSSH server. I've installed putty and super putty (i know not really relevant, but I want to be thorough.) on my desktop. I can connect to the laptop from the desktop using putty and Splunk will display the results of the command "splunk status" in putty, but any other command like "splunk btool inputs.conf list" or "splunk show web-port" doesn't return any results in putty. I'm assuming that the laptop still running the command but not returning the results in putty. i.e. a command prompt window is very quickly opening and displaying the results and just as quickly closing before i can even notice it. I'm assuming this because after i press enter for those commands on putty, there is a pause before putty shows command prompt/next line again.

please help.

0 Karma

woodcock
Esteemed Legend

There are several things including:
0: Your btool syntax is wrong; use inputs, not inputs.conf.
1: You should always run your shell/cmd/powershell as Administrator; otherwise stdout will be piped to a popup which will flash and disappear.
2: Some commands require passwords so if you do not specify CLI argument -auth user:PW then this may hang your window.
3: You could always redirect the output to a file and inspect the file.
4: These kinds of things are exactly why I hate running Splunk on Windows.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...