<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Run Python scripts with universal forwarder to modify files on the server in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/524234#M3771</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i would need to run a python script, using splunk's universal forwarder, on the servers where the forwarder is installed.&lt;/P&gt;&lt;P&gt;The goal of the script is to check the hostname in the input.conf file (in $ SPLUNK_HOME / etc / system / local) so that if the server hostname and the hostname in the input.conf file are different, the script change hostname in input.conf file and restart splunk.&lt;BR /&gt;If the hostnames are the same, it does nothing and exits the script.&lt;/P&gt;&lt;P&gt;The script must be run every night at 2:00 AM, and I would like once the app is created it will be distributed to all servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;import sys
import fileinput
import subprocess
import re

print("[+] Splunk Hostname Changer")


def get_hostname_to_command():
    hostC = subprocess.getoutput('hostname')
    print("[+] Result to hostname command: " + hostC)
    return hostC


def get_hostname_to_file(path):
    file = open(path,"r")
    hostRow = file.readlines()[1]
    hostF = re.search(r'[^host\s\=\s][A-Za-z]*[\-]*[A-Za-z]+',hostRow).group(0)
    print("[+] Hostname in inputfile.conf: " + hostF)
    return hostF


def hostname_check(hostC,hostF,path):
    if hostC != hostF:
        print("[-] Hostname mismatch. Change the hostname in input.conf!")
        for line in fileinput.input(path,inplace=True):
            line = line.replace(hostF, hostC)
            sys.stdout.write(line)
        print("[+] Hostname changed. Operation Complete!")
        print("[+] Restart Splunk...")
        subprocess.call(["C:\Program Files\SplunkUniversalForwarder\\bin\splunk.exe","restart"])
        print("[+] Restart Splunk completed!")
    else:
        print("[+] Hostname match. Exit to script!")


hostCommand = get_hostname_to_command()
hostFile = get_hostname_to_file("C:\Program Files\SplunkUniversalForwarder\etc\system\local\input.conf")
hostname_check(hostCommand,hostFile, "C:\Program Files\SplunkUniversalForwarder\etc\system\local\input.conf")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read some information scattered around the web and I still don't understand if this type of business is available or not.&lt;BR /&gt;Is it possible to do this?&lt;/P&gt;&lt;P&gt;I'm here for further informations.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;</description>
    <pubDate>Mon, 12 Oct 2020 14:34:06 GMT</pubDate>
    <dc:creator>antoniocarletto</dc:creator>
    <dc:date>2020-10-12T14:34:06Z</dc:date>
    <item>
      <title>Run Python scripts with universal forwarder to modify files on the server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/524234#M3771</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i would need to run a python script, using splunk's universal forwarder, on the servers where the forwarder is installed.&lt;/P&gt;&lt;P&gt;The goal of the script is to check the hostname in the input.conf file (in $ SPLUNK_HOME / etc / system / local) so that if the server hostname and the hostname in the input.conf file are different, the script change hostname in input.conf file and restart splunk.&lt;BR /&gt;If the hostnames are the same, it does nothing and exits the script.&lt;/P&gt;&lt;P&gt;The script must be run every night at 2:00 AM, and I would like once the app is created it will be distributed to all servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;import sys
import fileinput
import subprocess
import re

print("[+] Splunk Hostname Changer")


def get_hostname_to_command():
    hostC = subprocess.getoutput('hostname')
    print("[+] Result to hostname command: " + hostC)
    return hostC


def get_hostname_to_file(path):
    file = open(path,"r")
    hostRow = file.readlines()[1]
    hostF = re.search(r'[^host\s\=\s][A-Za-z]*[\-]*[A-Za-z]+',hostRow).group(0)
    print("[+] Hostname in inputfile.conf: " + hostF)
    return hostF


def hostname_check(hostC,hostF,path):
    if hostC != hostF:
        print("[-] Hostname mismatch. Change the hostname in input.conf!")
        for line in fileinput.input(path,inplace=True):
            line = line.replace(hostF, hostC)
            sys.stdout.write(line)
        print("[+] Hostname changed. Operation Complete!")
        print("[+] Restart Splunk...")
        subprocess.call(["C:\Program Files\SplunkUniversalForwarder\\bin\splunk.exe","restart"])
        print("[+] Restart Splunk completed!")
    else:
        print("[+] Hostname match. Exit to script!")


hostCommand = get_hostname_to_command()
hostFile = get_hostname_to_file("C:\Program Files\SplunkUniversalForwarder\etc\system\local\input.conf")
hostname_check(hostCommand,hostFile, "C:\Program Files\SplunkUniversalForwarder\etc\system\local\input.conf")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read some information scattered around the web and I still don't understand if this type of business is available or not.&lt;BR /&gt;Is it possible to do this?&lt;/P&gt;&lt;P&gt;I'm here for further informations.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 14:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/524234#M3771</guid>
      <dc:creator>antoniocarletto</dc:creator>
      <dc:date>2020-10-12T14:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Run Python scripts with universal forwarder to modify files on the server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/524235#M3772</link>
      <description>&lt;P&gt;Universal Forwarders do not come with Python so they cannot run Python scripts.&amp;nbsp; You'll need a heavy forwarder for that.&amp;nbsp; If you can't run heavy forwarders then you'll need to write a shell script that does the work.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 14:39:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/524235#M3772</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-12T14:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Run Python scripts with universal forwarder to modify files on the server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/577327#M10888</link>
      <description>&lt;P&gt;I found the solution&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Python-3-modular-input-on-a-universal-forwarder-version-8/m-p/485953" target="_blank"&gt;Python 3 modular input on a universal forwarder ve... - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Dec 2021 13:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/577327#M10888</guid>
      <dc:creator>feelcool</dc:creator>
      <dc:date>2021-12-04T13:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Run Python scripts with universal forwarder to modify files on the server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/609901#M13669</link>
      <description>&lt;P&gt;Is there a way to simulate that, i.e., hack. Say set up symlinks to python in Splunk's bin and lib directories?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 03:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Run-Python-scripts-with-universal-forwarder-to-modify-files-on/m-p/609901#M13669</guid>
      <dc:creator>marksheinbaum</dc:creator>
      <dc:date>2022-08-18T03:36:22Z</dc:date>
    </item>
  </channel>
</rss>

