Getting Data In

How to run simple shell script on Forwarding agent and send the standard output to Splunk indexer?

aruncse83
Explorer

Looking to run a script every minute on the splunk forwarders and would like to send the standard output to the splunk indexer. I wanted to achieve all this within splunk because this reduces the paper work and other approvals for me to get these deployed across the production application server. Script prints out the Free CPU, Memory , netstat and Load in key value pair and I would like this to be forwarded into its own sourcetype

Tags (3)
0 Karma

aruncse83
Explorer

I was looking to run these on Solaris , I am not sure if the SOS add on would help. But did write a quick shell script and used the steps from the link to schedule and run it every 60 seconds on the forwarder.

http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/ScriptSetup

0 Karma

MuS
SplunkTrust
SplunkTrust

Take a closer look at the S.o.S. Add-on https://apps.splunk.com/app/870/ within that Add-on you find a scripted input that almost does what you want. Other examples can be found in the Unix App Add-on https://apps.splunk.com/app/833/

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...