<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk query to see Linux patching in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500782#M17191</link>
    <description>&lt;P&gt;Depends on your distribution toolset (yum, zypper, apt, ...)&lt;/P&gt;

&lt;P&gt;Write a script to integrate patches etc. into your system. The Script should be able to analyse the installation and generate useful logdata four your  syslog (local or remote).&lt;BR /&gt;
 The TA for unix has an update-script, which is only useful for redhat or darwin based systems. For "linux", aka redhat-based distros, the output of yum check-update is parsed via awk.  So you have to use a tool for integrating the patches. &lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2019 19:28:30 GMT</pubDate>
    <dc:creator>st14014</dc:creator>
    <dc:date>2019-12-04T19:28:30Z</dc:date>
    <item>
      <title>Splunk query to see Linux patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500780#M17189</link>
      <description>&lt;P&gt;Hi , Our most of the splunk servers are Linux based systems , How can i create a splunk query to verify if Linux OS patch has been successful or not ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 22:06:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500780#M17189</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-12-03T22:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to see Linux patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500781#M17190</link>
      <description>&lt;P&gt;Hello. I would install the Linux add on to collect data about your operating system.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/About&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There's version.sh which would collect the data.&lt;/P&gt;

&lt;P&gt;Then I would figure out what the current version is on your situation and alert on hosts that need patching.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 06:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500781#M17190</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2019-12-04T06:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to see Linux patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500782#M17191</link>
      <description>&lt;P&gt;Depends on your distribution toolset (yum, zypper, apt, ...)&lt;/P&gt;

&lt;P&gt;Write a script to integrate patches etc. into your system. The Script should be able to analyse the installation and generate useful logdata four your  syslog (local or remote).&lt;BR /&gt;
 The TA for unix has an update-script, which is only useful for redhat or darwin based systems. For "linux", aka redhat-based distros, the output of yum check-update is parsed via awk.  So you have to use a tool for integrating the patches. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 19:28:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500782#M17191</guid>
      <dc:creator>st14014</dc:creator>
      <dc:date>2019-12-04T19:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to see Linux patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500783#M17192</link>
      <description>&lt;P&gt;Thank you so much for the update yes we do have that add-on and version.sh file is disabled , i will turn the logging for it.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 16:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500783#M17192</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-12-06T16:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query to see Linux patching</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500784#M17193</link>
      <description>&lt;P&gt;i am not aware of any script i got the file name on the add-on what needs to be turned on.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 16:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-query-to-see-Linux-patching/m-p/500784#M17193</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-12-06T16:38:09Z</dc:date>
    </item>
  </channel>
</rss>

