Deployment Architecture

Question on shell script for linux

darksky21
Path Finder

Hi i am new to splunk and recently just setup a forwarder (Ubuntu system) and a indexer (Window 7).
Would like to use shell script to forward data to indexer but not too sure how i should code the shell script for it to work. For example if i wan to forward info on (ls -l $Home) how should i put it in the script for splunk to read it?

the ls -l $Home should display something like:
drwxr-xr-x 2 test test 4096 Sep 16 17:47 Desktop
drwxr-xr-x 2 test test 4096 Sep 14 16:11 Documents
drwxr-xr-x 2 test test 4096 Sep 14 18:02 Downloads

i tried creating a test.sh with content (ls -l $Home) to test but it does not work.
Really hope someone would give me an example on this thanks.

Tags (2)
1 Solution

amit_saxena
Communicator

Hi,

You can write anything in the shell script. Just remember to make it executable and then use "scripted-inputs" method of data input to call that script.

Check out http://docs.splunk.com/Documentation/Splunk/latest/Data/Setupcustominputs#Add_a_scripted_input_via_i... for more details.

Regards,
Amit Saxena

View solution in original post

darksky21
Path Finder

Thanks it works after changing the script to executable

0 Karma

amit_saxena
Communicator

Hi,

You can write anything in the shell script. Just remember to make it executable and then use "scripted-inputs" method of data input to call that script.

Check out http://docs.splunk.com/Documentation/Splunk/latest/Data/Setupcustominputs#Add_a_scripted_input_via_i... for more details.

Regards,
Amit Saxena

darksky21
Path Finder

Thanks it works after changing the script to executable

0 Karma

linu1988
Champion

Make the shell script executable, chmod a+x tesh.sh then configure it in inputs.conf. It works.

kristian_kolb
Ultra Champion

And also, that may not be the first task you wish to try if you're just starting out. Try monitoring /var/log/messages or some similar log file, which a) has chronological timestamps and b) gets updated fairly often.

/K

0 Karma

lukejadamec
Super Champion

Have you configured inputs.conf to run the script?

0 Karma
Get Updates on the Splunk Community!

The Payment Operations Wake-Up Call: Why Financial Institutions Can't Afford ...

The same scenario plays out across financial institutions daily. A payment system fails at 11:30 AM on a busy ...

Make Your Case: A Ready-to-Send Letter for Getting Approval to Attend .conf25

Hello Splunkers, Want to attend .conf25 in Boston this year but not sure how to convince your manager? We've ...

Community Spotlight: A Splunk Expert's Journey

In the world of data analytics, some journeys leave a lasting impact not only on the individual but on the ...