Getting Data In

How to run simple shell script on Forwarding agent and send the standard output to Splunk indexer?

aruncse83
Explorer

Looking to run a script every minute on the splunk forwarders and would like to send the standard output to the splunk indexer. I wanted to achieve all this within splunk because this reduces the paper work and other approvals for me to get these deployed across the production application server. Script prints out the Free CPU, Memory , netstat and Load in key value pair and I would like this to be forwarded into its own sourcetype

Tags (3)
0 Karma

aruncse83
Explorer

I was looking to run these on Solaris , I am not sure if the SOS add on would help. But did write a quick shell script and used the steps from the link to schedule and run it every 60 seconds on the forwarder.

http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/ScriptSetup

0 Karma

MuS
SplunkTrust
SplunkTrust

Take a closer look at the S.o.S. Add-on https://apps.splunk.com/app/870/ within that Add-on you find a scripted input that almost does what you want. Other examples can be found in the Unix App Add-on https://apps.splunk.com/app/833/

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...