I have just set up a splunk VM to monitor my NextCloud VM, using the excellent instructions and dashboard from here: https://intranet.graabek.com/cloud/index.php/s/Lc9oXkaWNmQHBqG
I was missing info (hardware, shares, etc) and found that /opt/splunk/etc/apps/TA-nextcloud/bin/nextcloud-info.sh was failing when running curl.
Issue was traced to using an email as the “USER” name in /opt/splunk/etc/apps/TA-nextcloud/local/TA-nextcloud.conf. All my NextCloud logins use an email address.
After some googling about curl I replaced the ‘@’ in the USER email address with %40 i.e
#USER is a Nextcloud user ID that is a member of the “admin” group.
And now my dashboard is populated