Splunk Search

run script on remote machine

arun_kant_sharm
Path Finder

I am looking at running script which is stored on my local machine and I want to run that script on a remote machine. In that remote machine user not allow me to make a cron job , so I want to run a script from my machine to the remote machine.

Tags (1)
0 Karma

gouravdashtcs
Loves-to-Learn

Hello Arun,

I assume the local machine which you are referring to is having Splunk Enterprise installed in it and the remote machine which you are referring to is having Splunk Universal forwarder installed in it. And the connection of Splunk UF is properly made to local machine in which Splunk ES is installed.
In this case you can keep the script in $SPLUNK_HOME/ets/apps/,app_name/bin/

Then go to Settings --> Data Inputs --> Scripts (Add New), then follow the steps which will be prompted/asked to you.
In this way you will be able to fetch the data using scripted input from any machine in which UF is installed.

Hope this helps. Please let me know for any further clarifications.

0 Karma

Javoraqa
Engager

 

@gouravdashtcs 

Hi I am doing the same i have put my .sh file in local as well as in remote server and created a specific index for it, still can't see any events.
Can you please fill the gap where am i missing ?
Your help is appreciated !!!!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...