Splunk Enterprise

Powershell scripted input debug logging


Does anyone know how to log INFO and WARN log_level events to $SplunkHome\var\log\splunk\splunk-powershell.ps1.log or $SplunkHome\var\log\splunk\splunkd.log for debug purposes using the powershell input?

Using the code below in the script terminates it:


Write-Error -Message 'INFO test'




10-16-2020 12:47:05.4859538-5 ERROR Executing script=& "$SplunkHome/etc/apps/foo/bin/foo.ps1" for stanza=foo failed with exception=INFO test


The script does run correctly. I would just like to have some debug options. Thanks. 

Labels (1)
Tags (3)
0 Karma


Did you ever work this out? I've tried Write-Warning, but the output didn't go into the log or into the indexed output

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...