Deployment Architecture

Invoke Script in Splunk

sanjubaba
Path Finder

Is it possible to invoke powershell script in Splunk?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

I think that you're speaking of using a Powershell script for data input.

Anyway, you can use a scripted input (for more infos see at https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/ScriptedInputsIntro ).

In addition, you could see the Splunk_TA_Windows that uses many PS scripts (https://splunkbase.splunk.com/app/742/).

In few words, you can use the PS script in two ways:

  • writing a file:
    • create a script that writes results in a file,
    • put it in the bin folder of your app,
    • schedule it in Windows scheduler,
    • read the file with a monitor input;
  • Directly sending output to Splunk:
    • create a script that send output to video,
    • put it in the bin folder of your app,
    • schedule it in inputs.conf,
    • Universal Forwarder, executes it following the setted configuration and output is directly sent to Splunk.

Second choice is better because you can manage it all in Splunk.

Ciao.

Giuseppe

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.