Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

How to run basic PowerShell script on universal forwarder

$
0
0
I'm trying to do something very simple but for some reason I can not get it to work. I'm trying to run the basic PowerShell command below on a universal forwarder (on a Windows 10 workstation) but the output is not going to Splunk. One question I have is what sourcetype should I be using? Each PowerShell command will have a different output...so do I need to have a sourcetype for each command I run? (And I have read the article but its just not clicking for me https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/MonitorWindowsdatawithPowerShellscripts) Key points: *Workstation is connected to the deployment server *I am using a very basic custom add-on app that host the PowerShell command *Custom Add-on app info 2 directories -> local and metadata. The local folder has two files: app.conf and inputs.conf (which is below). [powershell://test-script] script = Get-Process | Select-Object Handles, NPM, PM, WS, VM, Id, ProcessName -Last 5 schedule = **system is not showing this correctly but it polls every minute** sourcetype = Windows:Process

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>