Getting Data In

Why is the interval setting in inputs.conf ignored?

mykol_j
Path Finder

Currently on v 9.0.3 (but has been happening forever).

On our universal forwarders we're using the Splunk provided bin apps for various things. In this example, I just noted the win_installed_apps.bat  is running 78 times in a 24 hour period, even though the interval is set to once every 24 hours:

[script://.\bin\win_installed_apps.bat]
disabled = 0
## Run once per day
interval = 86400
sourcetype = Script:InstalledApps

Other examples that are set for 86400 seconds include win_timesync_configuration.bat and win_timesync_status.bat that both run 39 times a day.

We have a home grown script to check for compliance set to run every hour (3600 seconds) and it runs every hour like it should. Why are so many others ignored?

Thoughts?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mykol_j,

I agree with @PickleRick, check the configurations using btool.

at the same time, setup (only for testing) a different interval, maybe the problem isn't the interval: e.g. execution rights on the script or the script location.

Ciao.

Giuseppe

0 Karma

mykol_j
Path Finder

Thanks, guys.

Guess I need to learn to use btool...

I know, I know, I've just been lazy...

Grazie.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

mykol_j
Path Finder

<heavy sigh>

PS C:\Program Files\SplunkUniversalForwarder\bin> .\btool.exe list inputs --debug
SPLUNK_HOME must be set. Stopping.

 

Never a dull moment...

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma

PickleRick
SplunkTrust
SplunkTrust

First things first - use the btool to verify that your effective configuration is what you think it is.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...