Splunk Dev

Data not indexing from same script on different servers


I have a ssh script that collects metrics from the server and prints that to stdout.
For some reason, the same script runs fine on one server, but on the other I'm just getting the headers indexed.
Not sure what I can do or where the prob is.

alt text

0 Karma


My guess is that the script doesn't produce results on that second server. So it probably prints out headers and then the data it collected...so if no data is collected, you just get headers.

Can you manually run the script on the server that just produces headers? And as the account that splunk runs as? And if you wrote the script, I believe if you write to stderr, those messages will get indexed to _internal. So you could put some error checking in the script so you can see what it's doing when.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...