Getting Data In

Why is the interval setting in inputs.conf ignored?

mykol_j
Path Finder

Currently on v 9.0.3 (but has been happening forever).

On our universal forwarders we're using the Splunk provided bin apps for various things. In this example, I just noted the win_installed_apps.bat  is running 78 times in a 24 hour period, even though the interval is set to once every 24 hours:

[script://.\bin\win_installed_apps.bat]
disabled = 0
## Run once per day
interval = 86400
sourcetype = Script:InstalledApps

Other examples that are set for 86400 seconds include win_timesync_configuration.bat and win_timesync_status.bat that both run 39 times a day.

We have a home grown script to check for compliance set to run every hour (3600 seconds) and it runs every hour like it should. Why are so many others ignored?

Thoughts?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mykol_j,

I agree with @PickleRick, check the configurations using btool.

at the same time, setup (only for testing) a different interval, maybe the problem isn't the interval: e.g. execution rights on the script or the script location.

Ciao.

Giuseppe

0 Karma

mykol_j
Path Finder

Thanks, guys.

Guess I need to learn to use btool...

I know, I know, I've just been lazy...

Grazie.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

mykol_j
Path Finder

<heavy sigh>

PS C:\Program Files\SplunkUniversalForwarder\bin> .\btool.exe list inputs --debug
SPLUNK_HOME must be set. Stopping.

 

Never a dull moment...

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma

PickleRick
SplunkTrust
SplunkTrust

First things first - use the btool to verify that your effective configuration is what you think it is.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...