Getting Data In

Universal forwarder -> Scheduled a Script Input

lpolo
Motivator

Hello,

Is it possible to scheduled a script input in a universal forwarder?

Thanks in advance.

Luciano

Tags (2)

lpolo
Motivator
0 Karma

araitz
Splunk Employee
Splunk Employee

Yes, absolutely. For example, we have many folks using our Windows and Unix apps and technical add-ons on our univeral forwarders, which are primarily scripted inputs.

araitz
Splunk Employee
Splunk Employee

Yes, the configuration is identical to the one on the indexer. The main thing is that the forwarder must be configured to send the data somewhere, as it does no indexing itself. You can download the Unix TA at http://splunk-base.splunk.com/apps/33800/splunk-for-unix-and-linux-technology-add-on and look in default/inputs.conf for an example.

0 Karma

lpolo
Motivator

Excellent.
Is it configured like in a regular indexer?
If not: Could you provide an example configuration to run a script every 4 hours?

Regards,
Lp

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...