Getting Data In

Why am I getting error "Could not find script on deployment client" trying to add a local script on the universal forwarder from the deployment server?

thejohn
Path Finder

How do I add a local script on the forwarder from the deployment server?
I've put the script on the Universal forwarder in $SPLUNK_HOME\bin\scripts\ and tried to configure it on the server like so:

Add Data -> Select Forwarder -> Source: Scripts -> Command: $SPLUNK_HOME\bin\scripts\scan.bat

and on the last step, submit, it says Could not find file $SPLUNK_HOMEbinscriptsscan.bat.
It seems like you can't specify scripts local to the UF? Only scripts on the server? Is this right or I am doing something wrong?

Also I know I can configure this in inputs.conf on the UF, but it would be much better to do this from the Splunk Web UI than to rdp to the UF each time I need to add a script.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can specify a script local to the UF in inputs.conf of a deployment app. While the UI may not allow this, you certainly can add a script://... entry on the Deployment Server directly and deploy that out to the UF.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can specify a script local to the UF in inputs.conf of a deployment app. While the UI may not allow this, you certainly can add a script://... entry on the Deployment Server directly and deploy that out to the UF.

martin_mueller
SplunkTrust
SplunkTrust

Feel free to submit a case to support requesting this feature.

0 Karma

thejohn
Path Finder

Oh ok that might work. But its a shame this can't be done in UI. You can monitor files and directories from UI, local to forwarders so I think you should be able to run local scripts too.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...