Getting Data In

How to run simple shell script on Forwarding agent and send the standard output to Splunk indexer?

Explorer

Looking to run a script every minute on the splunk forwarders and would like to send the standard output to the splunk indexer. I wanted to achieve all this within splunk because this reduces the paper work and other approvals for me to get these deployed across the production application server. Script prints out the Free CPU, Memory , netstat and Load in key value pair and I would like this to be forwarded into its own sourcetype

Tags (3)
0 Karma

Explorer

I was looking to run these on Solaris , I am not sure if the SOS add on would help. But did write a quick shell script and used the steps from the link to schedule and run it every 60 seconds on the forwarder.

http://docs.splunk.com/Documentation/Splunk/6.1.3/AdvancedDev/ScriptSetup

0 Karma

SplunkTrust
SplunkTrust

Take a closer look at the S.o.S. Add-on https://apps.splunk.com/app/870/ within that Add-on you find a scripted input that almost does what you want. Other examples can be found in the Unix App Add-on https://apps.splunk.com/app/833/

cheers, MuS

0 Karma