To answer your question. I ran two tests:
Test 1.
I ran ../etc/apps/Splunk_TA_nix/bin/ps.sh
I got the full output, including the processes that are missing on splunk. The output is large, 509 lines out output.
Test 2.
I ran the command you suggested
'ps -wweo uname,pid,psr,pcpu,cputime,pmem,rsz,vsz,tty,s,etime,args'
I received the same output. Again, my processes appear.
In splunk, I only see processes from root , in the output of the command line ps , a non root process does not even appear until the 309th line. So, it looks, to me, like a clear case of the entire output stream is not getting forwarded. It certainly looks like it is getting truncated.
I am attaching the entire output here for reference
https://drive.google.com/file/d/14fhE90bWMQQNCsv4Kz0D1B6WEytQ3mTo/view?usp=sharing
... View more