Getting Data In

How to run simple shell script on Forwarding agent and send the standard output to Splunk indexer?

aruncse83
Explorer

Looking to run a script every minute on the splunk forwarders and would like to send the standard output to the splunk indexer. I wanted to achieve all this within splunk because this reduces the paper work and other approvals for me to get these deployed across the production application server. Script prints out the Free CPU, Memory , netstat and Load in key value pair and I would like this to be forwarded into its own sourcetype

Tags (3)
0 Karma

aruncse83
Explorer

I was looking to run these on Solaris , I am not sure if the SOS add on would help. But did write a quick shell script and used the steps from the link to schedule and run it every 60 seconds on the forwarder.

http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/ScriptSetup

0 Karma

MuS
SplunkTrust
SplunkTrust

Take a closer look at the S.o.S. Add-on https://apps.splunk.com/app/870/ within that Add-on you find a scripted input that almost does what you want. Other examples can be found in the Unix App Add-on https://apps.splunk.com/app/833/

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...