Hi,
I am totally new to Splunk. Is there a way to monitor all installed packages?
Best regards,
nowami
Splunk can run scripts and index their output, so you could define a script that regularly polls the currently installed packages. For newly installed stuff you could also index apt logs or whatever package managers you have to supplement the polled data.
thank you for your answer. Could tell me how to index apt-logs (because splunk seems to be complete but the interface is quite complex to use). Btw, I have just found this post : https://answers.splunk.com/answers/115817/search-for-a-list-of-installed-packages-with-version-numbe.... but I didn't understand the answer, I didn't even understood if it is related to my need. Could you help please ?
Here are the relevant docs sections for...
...monitoring files: http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Monitorfilesanddirectories
...indexing outputs from scripts: http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Getdatafromscriptedinputs
@martin_mueller thank you so much
If you are using a nix app/add-on you could get the list of packages installed from index=os eventtype=package [ensure the inputs.conf is enabled for package]. Hope this helps
Additionally, what do you mean by "package"?
@martin_mueller I am using a debian machine and I want to get trace of any package that is installed on the machine because we are three admin working on it
What do you mean by "monitor"? What exactly are you trying to accomplish?
@richgalloway in fact, I am using a debian machine and I want to log any package that is installed on the machine