I have a scripted input in Splunk that sends it's data to Splunk via STDOUT. Is there any way to run the script on-demand and have the results sent to Splunk without restarting Splunk? Something like a "oneshot" cli method, but for scripted inputs, not for files.
If you write the output to a file in a sinkhole like, .../var/spool/splunk, then Splunk will consume it.
If you need the sourcetype to be the same as when it runs as a script then create a different sinkhole and specify the sourcetype
or same idea with saving the result of the script to a file and monitor the file with the correct sourcetype.
then you will have to clean the result file once a while.
You can do this, but splunk wont index the data necessarily:
./splunk cmd /opt/splunk/etc/apps/yourapp/bin/script.sh
You will see STDOUT/ERR from your script though