Getting Data In

How to monitor all installed packages?

nowami
New Member

Hi,

I am totally new to Splunk. Is there a way to monitor all installed packages?

Best regards,
nowami

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk can run scripts and index their output, so you could define a script that regularly polls the currently installed packages. For newly installed stuff you could also index apt logs or whatever package managers you have to supplement the polled data.

nowami
New Member

thank you for your answer. Could tell me how to index apt-logs (because splunk seems to be complete but the interface is quite complex to use). Btw, I have just found this post : https://answers.splunk.com/answers/115817/search-for-a-list-of-installed-packages-with-version-numbe.... but I didn't understand the answer, I didn't even understood if it is related to my need. Could you help please ?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

nowami
New Member

@martin_mueller thank you so much

0 Karma

lakshman239
Influencer

If you are using a nix app/add-on you could get the list of packages installed from index=os eventtype=package [ensure the inputs.conf is enabled for package]. Hope this helps

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Additionally, what do you mean by "package"?

0 Karma

nowami
New Member

@martin_mueller I am using a debian machine and I want to get trace of any package that is installed on the machine because we are three admin working on it

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What do you mean by "monitor"? What exactly are you trying to accomplish?

---
If this reply helps you, Karma would be appreciated.

nowami
New Member

@richgalloway in fact, I am using a debian machine and I want to log any package that is installed on the machine

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...