Splunk Enterprise

Why is scripted input not showing up in search results, but is running fine in server?

akgmail
Engager

Scripted input not showing up in search results, but is running fine in server

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's not a lot to go on.  Make sure you're searching the right index and time window.  How are you determining the SI is running fine?  Does _internal show the script is launched?  Are there any conditions where the script might "run fine", but produce no output?

---
If this reply helps you, Karma would be appreciated.
0 Karma

akgmail
Engager

The script is producing output when i run the script located at  /opt/splunkforwarder/etc/apps/custom_app/bin  in UF but it is not sending data to HF.

UF is configured in a way that it forwards data to HF and then to IDXer.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

How did you determine the UF is not send data to the HF?  Make sure you're searching the right index and time window. 

Do you see the UF's internal logs in the search head?  Does _internal show the script is launched?

---
If this reply helps you, Karma would be appreciated.
0 Karma

somesoni2
Revered Legend

Check if you see any error in the internal logs from the server where scripted input is running

index=_internal error yourscriptnamehere
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...