You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

获取Splunk Forwarder Management后台查询及设备安全工具检测方案

解决Splunk转发器查询及设备安全工具检测问题

一、修复30天内上报的转发器查询

你当前的REST查询端点不正确,Forwarder Management的Clients数据存储在/services/deployment/server/clients端点。以下是修正后的查询,可精准获取30天内上报的已安装Splunk Forwarder的设备:

| rest /services/deployment/server/clients count=0 splunk_server=local
| eval last_checkin = strptime(lastCheckinTime, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where last_checkin >= relative_time(now(), "-30d@d")
| table hostname serverClasses
| mvexpand serverClasses
| eval server_class = mvindex(split(serverClasses, ":"), 0)
| stats 
    values(server_class) as assigned_server_classes 
    dc(server_class) as server_class_count 
    by hostname
| rename hostname as client_name
| table client_name server_class_count assigned_server_classes

关键修正说明:

  • 使用正确的REST端点/services/deployment/server/clients获取部署客户端信息
  • 通过lastCheckinTime字段筛选30天内上报的设备,避免包含长期离线的转发器
  • 展开并解析serverClasses字段,提取实际的服务器类名称,而非原始嵌套字段

二、筛选未安装转发器的设备

结合你已有的全设备查询,使用set diff命令高效找出未在转发器列表中的设备(性能优于join):

| set diff [
    // 全设备查询
    index=* earliest=-30d latest=now
    | stats dc(host) as host_event_count by host
    | where host_event_count > 0
    | table host
] [
    // 修正后的转发器查询
    | rest /services/deployment/server/clients count=0 splunk_server=local
    | eval last_checkin = strptime(lastCheckinTime, "%Y-%m-%dT%H:%M:%S.%3N%z")
    | where last_checkin >= relative_time(now(), "-30d@d")
    | table hostname
    | rename hostname as host
]
| rename host as unmanaged_device
| table unmanaged_device

三、更简便的设备安全工具检测方法

除了通过转发器服务器类判断,还有以下几种高效方案:

1. 直接搜索安全工具日志

如果安全工具会向Splunk发送日志,直接搜索对应数据源即可判断设备是否安装:

index=security sourcetype=your_security_tool_log earliest=-30d
| stats dc(host) as log_count by host
| where log_count > 0
| table host

未出现在结果中的设备即为未安装或未上报日志的设备。

2. 利用Deployment Server部署状态

如果安全工具是通过Splunk Deployment Server推送的,可直接检查转发器上的部署状态:

| rest /services/deployment/server/clients count=0 splunk_server=local
| eval last_checkin = strptime(lastCheckinTime, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where last_checkin >= relative_time(now(), "-30d@d")
| spath output=security_tool_state path=serverClasses{@name="你的安全工具服务器类"}.stateOnClient
| table hostname security_tool_state
| where security_tool_state != "installed"

3. 系统级软件检查(Windows/Unix)

  • Windows:通过WMI查询已安装软件,需在转发器配置输入脚本收集数据:
    index=windows sourcetype=wmi:installed_software earliest=-30d
    | where DisplayName="你的安全工具名称"
    | stats dc(host) by host
    
  • Unix/Linux:通过脚本收集已安装包信息,再查询:
    index=unix sourcetype=rpm_packages earliest=-30d
    | where package_name="你的安全工具包名"
    | stats dc(host) by host
    

内容的提问来源于stack exchange,提问作者Jandre vd Merwe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 17:18:28