Deployment Architecture

How to determine which apps were downloaded and by what clients from the Deployment Server?

muebel
SplunkTrust
SplunkTrust

If I look at the Forwarder Management console of the Deployment Server, I'll find a summary of App Downloads in the last hour.

Is there any way to identify exactly which apps were downloaded, and by what clients?

0 Karma

lguinn2
Legend

Ah, this information is in the _internal index. The exact search will vary based on your version of Splunk, so you may have to play around with this a bit:

index=_internal component=DeployedApplication OR component= PackageDownloadRestHandler  sourcetype=splunkd 
| table _time log_level host app message
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...