Getting Data In

How to monitor all installed packages?

nowami
New Member

Hi,

I am totally new to Splunk. Is there a way to monitor all installed packages?

Best regards,
nowami

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk can run scripts and index their output, so you could define a script that regularly polls the currently installed packages. For newly installed stuff you could also index apt logs or whatever package managers you have to supplement the polled data.

nowami
New Member

thank you for your answer. Could tell me how to index apt-logs (because splunk seems to be complete but the interface is quite complex to use). Btw, I have just found this post : https://answers.splunk.com/answers/115817/search-for-a-list-of-installed-packages-with-version-numbe.... but I didn't understand the answer, I didn't even understood if it is related to my need. Could you help please ?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

nowami
New Member

@martin_mueller thank you so much

0 Karma

lakshman239
Influencer

If you are using a nix app/add-on you could get the list of packages installed from index=os eventtype=package [ensure the inputs.conf is enabled for package]. Hope this helps

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Additionally, what do you mean by "package"?

0 Karma

nowami
New Member

@martin_mueller I am using a debian machine and I want to get trace of any package that is installed on the machine because we are three admin working on it

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What do you mean by "monitor"? What exactly are you trying to accomplish?

---
If this reply helps you, Karma would be appreciated.

nowami
New Member

@richgalloway in fact, I am using a debian machine and I want to log any package that is installed on the machine

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...