获取Splunk Forwarder Management后台查询及设备安全工具检测方案
解决Splunk转发器查询及设备安全工具检测问题
一、修复30天内上报的转发器查询
你当前的REST查询端点不正确,Forwarder Management的Clients数据存储在/services/deployment/server/clients端点。以下是修正后的查询,可精准获取30天内上报的已安装Splunk Forwarder的设备:
| rest /services/deployment/server/clients count=0 splunk_server=local | eval last_checkin = strptime(lastCheckinTime, "%Y-%m-%dT%H:%M:%S.%3N%z") | where last_checkin >= relative_time(now(), "-30d@d") | table hostname serverClasses | mvexpand serverClasses | eval server_class = mvindex(split(serverClasses, ":"), 0) | stats values(server_class) as assigned_server_classes dc(server_class) as server_class_count by hostname | rename hostname as client_name | table client_name server_class_count assigned_server_classes
关键修正说明:
- 使用正确的REST端点
/services/deployment/server/clients获取部署客户端信息 - 通过
lastCheckinTime字段筛选30天内上报的设备,避免包含长期离线的转发器 - 展开并解析
serverClasses字段,提取实际的服务器类名称,而非原始嵌套字段
二、筛选未安装转发器的设备
结合你已有的全设备查询,使用set diff命令高效找出未在转发器列表中的设备(性能优于join):
| set diff [ // 全设备查询 index=* earliest=-30d latest=now | stats dc(host) as host_event_count by host | where host_event_count > 0 | table host ] [ // 修正后的转发器查询 | rest /services/deployment/server/clients count=0 splunk_server=local | eval last_checkin = strptime(lastCheckinTime, "%Y-%m-%dT%H:%M:%S.%3N%z") | where last_checkin >= relative_time(now(), "-30d@d") | table hostname | rename hostname as host ] | rename host as unmanaged_device | table unmanaged_device
三、更简便的设备安全工具检测方法
除了通过转发器服务器类判断,还有以下几种高效方案:
1. 直接搜索安全工具日志
如果安全工具会向Splunk发送日志,直接搜索对应数据源即可判断设备是否安装:
index=security sourcetype=your_security_tool_log earliest=-30d | stats dc(host) as log_count by host | where log_count > 0 | table host
未出现在结果中的设备即为未安装或未上报日志的设备。
2. 利用Deployment Server部署状态
如果安全工具是通过Splunk Deployment Server推送的,可直接检查转发器上的部署状态:
| rest /services/deployment/server/clients count=0 splunk_server=local | eval last_checkin = strptime(lastCheckinTime, "%Y-%m-%dT%H:%M:%S.%3N%z") | where last_checkin >= relative_time(now(), "-30d@d") | spath output=security_tool_state path=serverClasses{@name="你的安全工具服务器类"}.stateOnClient | table hostname security_tool_state | where security_tool_state != "installed"
3. 系统级软件检查(Windows/Unix)
- Windows:通过WMI查询已安装软件,需在转发器配置输入脚本收集数据:
index=windows sourcetype=wmi:installed_software earliest=-30d | where DisplayName="你的安全工具名称" | stats dc(host) by host - Unix/Linux:通过脚本收集已安装包信息,再查询:
index=unix sourcetype=rpm_packages earliest=-30d | where package_name="你的安全工具包名" | stats dc(host) by host
内容的提问来源于stack exchange,提问作者Jandre vd Merwe
相关产品推荐
相关产品推荐

