Getting Data In

Why is my oneshot command not working

tkw03
Communicator

I have a oneshot command thats returning strange error message. I have everything in [-paramteter value] format. Heres the command:

 

 

/opt/splunk/bin/splunk add oneshot host12345.messages -hostname host12345 –index nix_os –sourcetype syslog

 

 

 

and the response:

 

 

Parameters must be in the form '-parameter value'

 

 

 

Labels (2)
Tags (1)
0 Karma
1 Solution

tkw03
Communicator

Figured it out. this was the result of a bad copy/paste issue.

I re-wrote the command, no copying and it worked as expected.

Thanks!

View solution in original post

tkw03
Communicator

Figured it out. this was the result of a bad copy/paste issue.

I re-wrote the command, no copying and it worked as expected.

Thanks!

richgalloway
SplunkTrust
SplunkTrust

In the two versions of Splunk I checked, the add oneshot command takes a single argument.

$ splunk help add oneshot

adds onetime file input

Syntax:

        None

Objects:

        add oneshot                             adds onetime file input

Required Parameters:

        (For add oneshot)
                source                          name of a file to add to inputs

Optional Parameters:

        None
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...