Getting Data In

How to monitor all installed packages?

nowami
New Member

Hi,

I am totally new to Splunk. Is there a way to monitor all installed packages?

Best regards,
nowami

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk can run scripts and index their output, so you could define a script that regularly polls the currently installed packages. For newly installed stuff you could also index apt logs or whatever package managers you have to supplement the polled data.

nowami
New Member

thank you for your answer. Could tell me how to index apt-logs (because splunk seems to be complete but the interface is quite complex to use). Btw, I have just found this post : https://answers.splunk.com/answers/115817/search-for-a-list-of-installed-packages-with-version-numbe.... but I didn't understand the answer, I didn't even understood if it is related to my need. Could you help please ?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

nowami
New Member

@martin_mueller thank you so much

0 Karma

lakshman239
Influencer

If you are using a nix app/add-on you could get the list of packages installed from index=os eventtype=package [ensure the inputs.conf is enabled for package]. Hope this helps

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Additionally, what do you mean by "package"?

0 Karma

nowami
New Member

@martin_mueller I am using a debian machine and I want to get trace of any package that is installed on the machine because we are three admin working on it

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What do you mean by "monitor"? What exactly are you trying to accomplish?

---
If this reply helps you, Karma would be appreciated.

nowami
New Member

@richgalloway in fact, I am using a debian machine and I want to log any package that is installed on the machine

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...