Getting Data In

How to run simple shell script on Forwarding agent and send the standard output to Splunk indexer?

aruncse83
Explorer

Looking to run a script every minute on the splunk forwarders and would like to send the standard output to the splunk indexer. I wanted to achieve all this within splunk because this reduces the paper work and other approvals for me to get these deployed across the production application server. Script prints out the Free CPU, Memory , netstat and Load in key value pair and I would like this to be forwarded into its own sourcetype

Tags (3)
0 Karma

aruncse83
Explorer

I was looking to run these on Solaris , I am not sure if the SOS add on would help. But did write a quick shell script and used the steps from the link to schedule and run it every 60 seconds on the forwarder.

http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/ScriptSetup

0 Karma

MuS
Legend

Take a closer look at the S.o.S. Add-on https://apps.splunk.com/app/870/ within that Add-on you find a scripted input that almost does what you want. Other examples can be found in the Unix App Add-on https://apps.splunk.com/app/833/

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...