Deployment Architecture

How to search what universal forwarder version and machine type my hosts are running and save this as a report?

pil321
Communicator

The Deployment Monitor gives you some good information and the Forwarder Manager gives you some good info as well. But, they don't let you save the information they collect as a report.

So, I would like to be able to do a search to find out what version universal forwarder my hosts are running (which Deployment Monitor does) AND what machine type they are running (which Forwarder Management does) AND be able to save the search as a report (which the Search & Reporting app does). I can't get a peek as to how the apps get this information, since they don't give you a way to open them in search mode.

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

We highly recommend you use the Splunk on Splunk app S.o.S instead of Deployment Monitor. If you haven't already, try it out. You'll really like what you see.

In order to see what searches have been run , no matter what app you're in, click on the Activity menu and choose Jobs from the dropdown. From here you will be able to see the exact search that was run. Please note the context dropdowns (filtered by app and owner). If you click on the search text (it shows up as a link), it will open in the search view.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

We highly recommend you use the Splunk on Splunk app S.o.S instead of Deployment Monitor. If you haven't already, try it out. You'll really like what you see.

In order to see what searches have been run , no matter what app you're in, click on the Activity menu and choose Jobs from the dropdown. From here you will be able to see the exact search that was run. Please note the context dropdowns (filtered by app and owner). If you click on the search text (it shows up as a link), it will open in the search view.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...