Getting Data In

Reporting clients with the timestamp workaround (datetime.xml file) in place

oliverj
Communicator

Is there a way to check which hosts (universal forwarders or splunk enterprise) have the updated datetime.xml installed?
We have several different groups that send us logs from an internal network via a heavy forwarder, so I can see their splunkd logs, but there seems to be no record of the new file.
On the heavy installs, It reports properly.
On the universal forwarders, I was hoping that it would fail the file validation at startup and send the log to _internal, but even though "splunk.exe validate files" shows there is a change, nothing shows up in the splunkd log or at startup.

I am trying to generate a list of all hosts that do not have the file installed.

I realize that this timestamp issue may not affect certain log types, but we are not in a position to pick/choose which ones will work, so our strategy will be to apply the workaround to 100% of the instances.

0 Karma
1 Solution

oliverj
Communicator

Per Splunk support, the universal forwarders do not generate a usable message in their logs, although the heavy/full versions do.
It is possible to build a script that you can install as an app that will to a checksum check, but we are not in a position to install apps across devices we do not own.
So, manual checks it is.

View solution in original post

0 Karma

oliverj
Communicator

Per Splunk support, the universal forwarders do not generate a usable message in their logs, although the heavy/full versions do.
It is possible to build a script that you can install as an app that will to a checksum check, but we are not in a position to install apps across devices we do not own.
So, manual checks it is.

0 Karma

ycefalas
Loves-to-Learn Lots

Deployment server can produce a list of Splunk versions for UF/Splunk which can indicate that the endpoint being on a non patch UF.

0 Karma

oliverj
Communicator

Yes, but in our case, we only updated the XML.
Software updates would be better, but the release turnaround in our environment is prohibitively slow for an emergency like this.

0 Karma

oliverj
Communicator

Any suggestions here?
Having a hard time coming up with a verification method.

0 Karma
Get Updates on the Splunk Community!

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...