Splunk Enterprise

Why is scripted input not showing up in search results, but is running fine in server?

akgmail
Explorer

Scripted input not showing up in search results, but is running fine in server

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's not a lot to go on.  Make sure you're searching the right index and time window.  How are you determining the SI is running fine?  Does _internal show the script is launched?  Are there any conditions where the script might "run fine", but produce no output?

---
If this reply helps you, Karma would be appreciated.
0 Karma

akgmail
Explorer

The script is producing output when i run the script located at  /opt/splunkforwarder/etc/apps/custom_app/bin  in UF but it is not sending data to HF.

UF is configured in a way that it forwards data to HF and then to IDXer.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

How did you determine the UF is not send data to the HF?  Make sure you're searching the right index and time window. 

Do you see the UF's internal logs in the search head?  Does _internal show the script is launched?

---
If this reply helps you, Karma would be appreciated.
0 Karma

somesoni2
Revered Legend

Check if you see any error in the internal logs from the server where scripted input is running

index=_internal error yourscriptnamehere
0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...