Deployment Architecture

How to collect output from "rpm -qa --list" command into Splunk?

joesrepsol
Path Finder

Hello!

Looking to do some patch monitoring on our *nix boxes and find the "rpm -qa --list" command extremely useful. But struggling to find the best way to get this information into Splunk from all our forwarders. Can I have splunk run this command and ingest the output?

Thought of using another tool to collect the output and store in DB somewhere, then use DB Connect to ingest, but was hoping to skip a step. Thoughts? Suggestions?

Thanks everyone!

(Splunk Enterprise 7.1 Deployment)

Joe

0 Karma

ddrillic
Ultra Champion

Please use the Setting up a scripted input approach.

0 Karma

joesrepsol
Path Finder

Reading thru that now... hadn't figured out exactly how I would be able to run this rpm command using python. Output is pretty basic.. 2 columns. If I could grab that output and throw into an index that would be awesome.

Anymore help on how to do just that?

0 Karma
Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

Splunk Developers: Go Beyond the Dashboard with These .Conf25 Sessions

  Whether you’re building custom apps, diving into SPL2, or integrating AI and machine learning into your ...

Index This | How do you write 23 only using the number 2?

July 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...