Getting Data In

Why is my oneshot command not working

tkw03
Communicator

I have a oneshot command thats returning strange error message. I have everything in [-paramteter value] format. Heres the command:

 

 

/opt/splunk/bin/splunk add oneshot host12345.messages -hostname host12345 –index nix_os –sourcetype syslog

 

 

 

and the response:

 

 

Parameters must be in the form '-parameter value'

 

 

 

Labels (2)
Tags (1)
0 Karma
1 Solution

tkw03
Communicator

Figured it out. this was the result of a bad copy/paste issue.

I re-wrote the command, no copying and it worked as expected.

Thanks!

View solution in original post

tkw03
Communicator

Figured it out. this was the result of a bad copy/paste issue.

I re-wrote the command, no copying and it worked as expected.

Thanks!

richgalloway
SplunkTrust
SplunkTrust

In the two versions of Splunk I checked, the add oneshot command takes a single argument.

$ splunk help add oneshot

adds onetime file input

Syntax:

        None

Objects:

        add oneshot                             adds onetime file input

Required Parameters:

        (For add oneshot)
                source                          name of a file to add to inputs

Optional Parameters:

        None
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...