Skip to main content

Splunk Dispatch Script

______________________________________________________________________________________________________

Script examples written by Travis Hutchings

thutch901@gmail.com

971.226.6732

Splunk Dispatch Directory count and size. If it gets above 2000 entries it stops forwarding.

_______________________________________________________

Command Examples for Dispatch CLI options.

df -h $SPLUNK_HOME/var/run/dispatch

cd  $SPLUNK_HOME/var/run/dispatch

ls -l | head -4

ls -l tail -4

Script Example for Dispatch Alert Cron Script

#!/bin/bash
#Version: 1.2
#Owner: Optiv NGSOC
#Document Purpose: Pull list of all active log sources in the last week and email them to appropriate recipients

clientName="Your Company"
emailFrom="Splunk_Dispatch_rp.as@yourco.com"
emailTo="systemadmins@yourco.com"
listFile="/splunk/scripts/dispatch_length.csv"
bodyFile="/splunk/scripts/dispatch_length.txt"

Echo "Dispatch Directory Progress" >> $listFile
ls -l $SPLUNK_HOME/var/run/dispatch | head -6' >> $listFile

ls -l $SPLUNK_HOME/var/run/dispatch | | tail -6' >> $listFile

Echo "Dispatch Directory Number of Entries" >> $listFile

ls -l $SPLUNK_HOME/var/run/dispatch | wc -l >> $listFile

cat  $listFile >> $bodyFile

/bin/mail -s "Dispatch Directory Progress and Entries" -r "$emailFrom" -a "$listFile" $emailTo < /splunk/scripts/dispatch_length.txt

rm /splunk/scripts/dispatch_length.csv
rm x/splunk/scripts/dispatch_length.txt




Comments

Popular posts from this blog

Qradar Scripts and Results Part 1. Disk Space and Qradar Persistent Queue

______________________________________________________________________________________________________ Script examples written by Travis Hutchings thutch901@gmail.com 971.226.6732 _______________________________________________________ Disk Space and Alerting Results specific to Qradar servers and environments. General Linux script concepts can also be applied to system administration concepts. This disk space script utilizes a few Qradar support functions. 1. Disk Space Alerting and results in /store volume List disk space for all Qradar servers: df- h /opt/qradar/support/all_servers.sh -a '15%' 'df -h /store' >> $listFile List the top of the directory to see file dates and times to determine if Persistent Queue is processing: /opt/qradar/support/all_servers.sh -a '15%' 'ls -l /store/persistent_queue/ecs-ec-ingress.ecs-ec-ingress | head -6' >> $listFile Bottom of the Persistent Queue and seeing if results are processing: /opt/qradar/suppor...

Qradar- PSQL Report Development for EPS by log source result

EPS by logsource with QRADAR PSQL query tests and research By Travis Hutchings thutch901@gmail.com 971.226.6732  psql -A -F"," -U qradar -c "select sensordevice.id, sensordevice.hostname, sensordevice.devicename, sensordevicetype.devicetypename, to_timestamp(sensordevice.timestamp_last_seen/1000) from sensordevice, sensordevicetype where sensordevice.devicetypeid = sensordevicetype.id and sensordevice.deviceenabled = 't' and sensordevice.devicename not ilike '%wincollect%' and to_timestamp(sensordevice.timestamp_last_seen/1000) > now() - interval '30 days' order by to_timestamp(timestamp_last_seen/1000) desc" psql -A -F"," -U qradar -c "select sensordevice.id, sensordevice.hostname, sensordevice.devicename, sensordevicetype.devicetypename, to_timestamp(sensordevice.timestamp_last_seen/1000), to_timestamp(round(sensordevice.creationdate/1000) from sensordevice, sensordevicetype where sensordevice.devicetypeid = sensordevicety...

Splunk Log Forwarding Configuration Steps

Splunk Log Forwarding Configuration Steps: There are multiple ways to send linux logs to splunk like using splunk linux app, splunk universal forwarder or syslog. Best and performance reliable way is to install splunk universal forwarder on linux machines for which you wish to forward data.Splunk universal forwarder will act as agent for log collection.It will collect logs and will forward to indexer.We can  also use syslog for log collection and then install splunk forwarder on it and then forward data from syslog server to splunk indexer.Below we have provided steps for most reliable method to add linux logs to splunk For syslog installation and configuration follow steps give at below link: Refer below steps to add linux logs to splunk Step 1: On Splunk server (receiver) Download/install Splunk TA for Unix and Linux to the Splunk server (receiver) and enabled it by going to Manager|Apps|Enable Step 2: On host you want to collect data from (sender) Download and install the Splu...