Splunk Enterprise

How can I automatically retrieve latest splunk version?

camar
Engager

Hi,

I'd like to create a script to automate splunk hole process install. And im wondering how i could retrieve automaticaly the latest version of the package with wget command.

instead of getting by myself by log in splunk website with my credentials, is it possible to provide my login credentials directly in the wget command ?

In other words, i would like to calibrate my wget command to say it : hey wget, go get splunk latest version, here are my credentials...

At 1st glance, i would say that that python or ansible could help but I don't know how to take it...

Thanks in advance for your suggestions.

Labels (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Give this shell script a try (comment/uncomment lines based on what type of product you want to download)

URL="https://www.splunk.com/en_us/download/splunk-enterprise.html"
#URL="https://www.splunk.com/en_us/download/universal-forwarder.html"
#OS_REGEX="linux-2\.6-x86_64\.rpm"
OS_REGEX="Linux-x86_64\.tgz"
#OS_REGEX="x64-release.msi"
RESPONSE=`curl -s --connect-timeout 10 --max-time 10 $URL`
LINK=`echo $RESPONSE | egrep -o "data-link=\"https://[^\"]+-${OS_REGEX}\"" | cut -c12- | rev | cut -c2- | rev`
echo $LINK
wget --no-check-certificate -P /tmp $LINK

View solution in original post

0 Karma

somesoni2
Revered Legend

Give this shell script a try (comment/uncomment lines based on what type of product you want to download)

URL="https://www.splunk.com/en_us/download/splunk-enterprise.html"
#URL="https://www.splunk.com/en_us/download/universal-forwarder.html"
#OS_REGEX="linux-2\.6-x86_64\.rpm"
OS_REGEX="Linux-x86_64\.tgz"
#OS_REGEX="x64-release.msi"
RESPONSE=`curl -s --connect-timeout 10 --max-time 10 $URL`
LINK=`echo $RESPONSE | egrep -o "data-link=\"https://[^\"]+-${OS_REGEX}\"" | cut -c12- | rev | cut -c2- | rev`
echo $LINK
wget --no-check-certificate -P /tmp $LINK
0 Karma

camar
Engager

Hello,

iam happy to say you that your code helped out as it works perfectly so far.

nom iam trying to study the construction you've used for $LINK.

i'll ping you if my head blows 🙂

And thank you

i mean it

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...