Monitoring Splunk

How to find first connect time/version of a universal Forwarder?

att35
Builder

Hi,

I am looking for a way to track when a new Splunk Forwarder connects along with the version. Was hoping to find some relevant field on Deployment Server (/services/deployment/server/clients) but I could only see lastPhoneHomeTime, nothing for when it first connected to the system.

Is it possible to get this information, either from Deployment Server or Forwarder's internal logs?

 

Thanks,

~ Abhi

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Even if (I suppose the info must be there since the DS shows it - it searches the _internal index) you do that, remember that you're limited by _internal index's retention period.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...