Splunk Enterprise

Why is scripted input not showing up in search results, but is running fine in server?

akgmail
Engager

Scripted input not showing up in search results, but is running fine in server

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's not a lot to go on.  Make sure you're searching the right index and time window.  How are you determining the SI is running fine?  Does _internal show the script is launched?  Are there any conditions where the script might "run fine", but produce no output?

---
If this reply helps you, Karma would be appreciated.
0 Karma

akgmail
Engager

The script is producing output when i run the script located at  /opt/splunkforwarder/etc/apps/custom_app/bin  in UF but it is not sending data to HF.

UF is configured in a way that it forwards data to HF and then to IDXer.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

How did you determine the UF is not send data to the HF?  Make sure you're searching the right index and time window. 

Do you see the UF's internal logs in the search head?  Does _internal show the script is launched?

---
If this reply helps you, Karma would be appreciated.
0 Karma

somesoni2
Revered Legend

Check if you see any error in the internal logs from the server where scripted input is running

index=_internal error yourscriptnamehere
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...