Deployment Architecture

Send Forwarder data from Splunk server as arguments

kuzkuz
Explorer

Hello,

We have a deployment App (modular Powershell) used on clients using the forwarder, I'm interested in passing data from Splunk Enterprise into the clients so this data can be used by the App to take actions, run specific sections, etc..

Can we send specific data to each forwarder from the server?

For example:
1. Run actions based on the ESX CPU that the Client is hosted
2. Run some kind of validation test based on a product reported from a different data source)

Thanks!

0 Karma

kuzkuz
Explorer

For anyone else looking an answer, we implemented a set of PowerShell functions that read data from Splunk using REST API and taking the needed action based on the result

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I've done something similar but used an external tool (UC4 Automic) to do this. Splunk would trigger an alert which would then kick off the workflow in Automic. If you didn't have a workflow automation tool, then you will need to script this yourself.

First setup an alert in Splunk which will send a REST call to your remote servers which would then kick off a script which can validate your conditions

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...