Getting Data In

How to monitor all installed packages?

nowami
New Member

Hi,

I am totally new to Splunk. Is there a way to monitor all installed packages?

Best regards,
nowami

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk can run scripts and index their output, so you could define a script that regularly polls the currently installed packages. For newly installed stuff you could also index apt logs or whatever package managers you have to supplement the polled data.

nowami
New Member

thank you for your answer. Could tell me how to index apt-logs (because splunk seems to be complete but the interface is quite complex to use). Btw, I have just found this post : https://answers.splunk.com/answers/115817/search-for-a-list-of-installed-packages-with-version-numbe.... but I didn't understand the answer, I didn't even understood if it is related to my need. Could you help please ?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

nowami
New Member

@martin_mueller thank you so much

0 Karma

lakshman239
Influencer

If you are using a nix app/add-on you could get the list of packages installed from index=os eventtype=package [ensure the inputs.conf is enabled for package]. Hope this helps

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Additionally, what do you mean by "package"?

0 Karma

nowami
New Member

@martin_mueller I am using a debian machine and I want to get trace of any package that is installed on the machine because we are three admin working on it

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What do you mean by "monitor"? What exactly are you trying to accomplish?

---
If this reply helps you, Karma would be appreciated.

nowami
New Member

@richgalloway in fact, I am using a debian machine and I want to log any package that is installed on the machine

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...