I activated *NIX, and it's collecting all other types of data about the system, but I get no data entries for lsof. The script runs correctly when I invoke it myself (/opt/splunk/etc/apps/unix/bin/lsof.sh), and the input source is definitely enabled.
My uname: Linux 2.6.9-023stab051.3-enterprise #1 SMP Wed Nov 4 19:28:06 MSK 2009 i686 i686 i386 GNU/Linux
Posted our workaround for this bug here: http://splunk-base.splunk.com/answers/78143/why-is-lsof_sossh-not-returning-any-data
Did that work for you ?
What search command are you running?
Does "sourcetype=lsof index=os earliest=-1d" return any events?