Deployment Architecture

How to search what universal forwarder version and machine type my hosts are running and save this as a report?

pil321
Communicator

The Deployment Monitor gives you some good information and the Forwarder Manager gives you some good info as well. But, they don't let you save the information they collect as a report.

So, I would like to be able to do a search to find out what version universal forwarder my hosts are running (which Deployment Monitor does) AND what machine type they are running (which Forwarder Management does) AND be able to save the search as a report (which the Search & Reporting app does). I can't get a peek as to how the apps get this information, since they don't give you a way to open them in search mode.

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

We highly recommend you use the Splunk on Splunk app S.o.S instead of Deployment Monitor. If you haven't already, try it out. You'll really like what you see.

In order to see what searches have been run , no matter what app you're in, click on the Activity menu and choose Jobs from the dropdown. From here you will be able to see the exact search that was run. Please note the context dropdowns (filtered by app and owner). If you click on the search text (it shows up as a link), it will open in the search view.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

We highly recommend you use the Splunk on Splunk app S.o.S instead of Deployment Monitor. If you haven't already, try it out. You'll really like what you see.

In order to see what searches have been run , no matter what app you're in, click on the Activity menu and choose Jobs from the dropdown. From here you will be able to see the exact search that was run. Please note the context dropdowns (filtered by app and owner). If you click on the search text (it shows up as a link), it will open in the search view.

Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...