I have a linux-based universal forwarder that gets multiple apps from the deployment server. I'd like to find out exactly what apps it's receiving. What command to I run on the forwarder to get a list?
grep "<app" $SPLUNK_HOME/var/run/serverclass.xml | awk -F= '{ print $2 }' | awk '{ print $1 }'
I can never remember this but its:
./splunk display app