Splunk Dev

Data not indexing from same script on different servers

muriloalves
Explorer

I have a ssh script that collects metrics from the server and prints that to stdout.
For some reason, the same script runs fine on one server, but on the other I'm just getting the headers indexed.
Not sure what I can do or where the prob is.
Thanks,

alt text

0 Karma

maciep
Champion

My guess is that the script doesn't produce results on that second server. So it probably prints out headers and then the data it collected...so if no data is collected, you just get headers.

Can you manually run the script on the server that just produces headers? And as the account that splunk runs as? And if you wrote the script, I believe if you write to stderr, those messages will get indexed to _internal. So you could put some error checking in the script so you can see what it's doing when.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...