Getting Data In

Universal forwarder -> Scheduled a Script Input

lpolo
Motivator

Hello,

Is it possible to scheduled a script input in a universal forwarder?

Thanks in advance.

Luciano

Tags (2)

lpolo
Motivator
0 Karma

araitz
Splunk Employee
Splunk Employee

Yes, absolutely. For example, we have many folks using our Windows and Unix apps and technical add-ons on our univeral forwarders, which are primarily scripted inputs.

araitz
Splunk Employee
Splunk Employee

Yes, the configuration is identical to the one on the indexer. The main thing is that the forwarder must be configured to send the data somewhere, as it does no indexing itself. You can download the Unix TA at http://splunk-base.splunk.com/apps/33800/splunk-for-unix-and-linux-technology-add-on and look in default/inputs.conf for an example.

0 Karma

lpolo
Motivator

Excellent.
Is it configured like in a regular indexer?
If not: Could you provide an example configuration to run a script every 4 hours?

Regards,
Lp

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...