Deployment Architecture

How to collect output from "rpm -qa --list" command into Splunk?

joesrepsol
Path Finder

Hello!

Looking to do some patch monitoring on our *nix boxes and find the "rpm -qa --list" command extremely useful. But struggling to find the best way to get this information into Splunk from all our forwarders. Can I have splunk run this command and ingest the output?

Thought of using another tool to collect the output and store in DB somewhere, then use DB Connect to ingest, but was hoping to skip a step. Thoughts? Suggestions?

Thanks everyone!

(Splunk Enterprise 7.1 Deployment)

Joe

0 Karma

ddrillic
Ultra Champion

Please use the Setting up a scripted input approach.

0 Karma

joesrepsol
Path Finder

Reading thru that now... hadn't figured out exactly how I would be able to run this rpm command using python. Output is pretty basic.. 2 columns. If I could grab that output and throw into an index that would be awesome.

Anymore help on how to do just that?

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...