Splunk Enterprise

Why is linux script data showing the correct output but not getting correct data?

SK2
Loves-to-Learn

Configured the script based app for the databases which brings the data as follows. As mentioned below. 

When I am running the script at UF corrected expeced output. But when I push an application containg the same script it is fetching me different output.

Expected data after running the script in the UF is as below. 
Date, datname="sql", age="00:00:00"

Output we are receiving at splunk SH is like below. 
Date, datname="datname", age="age"

The script is kept in the location -> /opt/splunkforwarder/etc/apps/appname/bin - scripts  and /opt/splunkforwarder/etc/apps/appname/local - inputs.conf

For troubleshooting I have followed below steps. 
Removed and Pushed the app again
Tried restarting the UF

Can any one know or faced similar issue.
Please help me on this. 

 

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...