Deployment Architecture

How to determine which apps were downloaded and by what clients from the Deployment Server?

muebel
SplunkTrust
SplunkTrust

If I look at the Forwarder Management console of the Deployment Server, I'll find a summary of App Downloads in the last hour.

Is there any way to identify exactly which apps were downloaded, and by what clients?

0 Karma

lguinn2
Legend

Ah, this information is in the _internal index. The exact search will vary based on your version of Splunk, so you may have to play around with this a bit:

index=_internal component=DeployedApplication OR component= PackageDownloadRestHandler  sourcetype=splunkd 
| table _time log_level host app message
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...