Deployment Architecture

How to collect output from "rpm -qa --list" command into Splunk?

joesrepsol
Path Finder

Hello!

Looking to do some patch monitoring on our *nix boxes and find the "rpm -qa --list" command extremely useful. But struggling to find the best way to get this information into Splunk from all our forwarders. Can I have splunk run this command and ingest the output?

Thought of using another tool to collect the output and store in DB somewhere, then use DB Connect to ingest, but was hoping to skip a step. Thoughts? Suggestions?

Thanks everyone!

(Splunk Enterprise 7.1 Deployment)

Joe

0 Karma

ddrillic
Ultra Champion

Please use the Setting up a scripted input approach.

0 Karma

joesrepsol
Path Finder

Reading thru that now... hadn't figured out exactly how I would be able to run this rpm command using python. Output is pretty basic.. 2 columns. If I could grab that output and throw into an index that would be awesome.

Anymore help on how to do just that?

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...