Deployment Architecture

I received a new release available notification on my search head. Where does the notification come from?



When connecting to my search head, I got a notification about a new release being available.

However my search head is already up to date, same for my indexer. I have a few additional Splunk Enterprise server connected with misc. roles (Heavy forwarder, etc.) so I assume one of them has not been properly upgraded yet.

Eventually I will find out which one but I was wondering if we can find this info directly from Splunk, typically what is the search ran behind the process displaying this kind of notification?



I'm getting the same notification.. does anyone know how to disable this check?

