Getting Data In

Splunk is not Indexing Scripted Input Data

rsantoso_splunk
Splunk Employee
Splunk Employee

Splunk is not indexing the data through the Scripted input.

The input is working for the on-premise servers, the data input is through a universal forwarder. The same setup being configured, however, it is not working for the new host.

Tags (1)
0 Karma
1 Solution

rsantoso_splunk
Splunk Employee
Splunk Employee

1.) To list the non-internal indexes and non-internal indexes

a. To list of all non-internal indexes:
| eventcount summarize=false index=* | dedup index | fields index

b. To list of all sourcetype within the non-internal indexes:
| tstats count where index=* by index, sourcetype

2.) inputs.conf

a. The configuration for scripts needs to be in formatted with script rather than monitor
b. The script need to be located at the $SPLUNK_HOME/bin/scripts
Example:
[script:///opt/splunkforwarder/bin/scripts/client-stats.sh]

3.) The scripts need the environment setup and the jar file to run.
Copy the setup env file and the jar file to the $SPLUNK_HOME/bin/scripts.
Change the permission and ownership of the file accordingly.

View solution in original post

0 Karma

rsantoso_splunk
Splunk Employee
Splunk Employee

1.) To list the non-internal indexes and non-internal indexes

a. To list of all non-internal indexes:
| eventcount summarize=false index=* | dedup index | fields index

b. To list of all sourcetype within the non-internal indexes:
| tstats count where index=* by index, sourcetype

2.) inputs.conf

a. The configuration for scripts needs to be in formatted with script rather than monitor
b. The script need to be located at the $SPLUNK_HOME/bin/scripts
Example:
[script:///opt/splunkforwarder/bin/scripts/client-stats.sh]

3.) The scripts need the environment setup and the jar file to run.
Copy the setup env file and the jar file to the $SPLUNK_HOME/bin/scripts.
Change the permission and ownership of the file accordingly.

View solution in original post

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!