Other Usage

Version check

uagraw01
Builder

Hello Splunkers!!

 

How to check the version of all the add-ons we  are using on heavy forwarders. Like DB connect, solarwinds and so on by using any rest command in splunk.

 

Thanks in Advance.

 

 

Labels (1)
Tags (1)
0 Karma

uagraw01
Builder

@gcusello @aasabatini  Why i was asked this question. Because i am upgrading my all the heavy forwarders and all the add-ons we have configured on HFs. So i need to make plan. I have to make compatible metrics also to support latest HF version with the latest version of add-ons. If there is any recommended approach then please let me know.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01,

about Splunk version, you could also use the Monitoring Console to have them.

About Add-Ons, you could use a Deployment server to deploy Add-Ons to the HFs so, you'll be sure about the version of all Add-Ons and you'll be able to centrally manage them.

Ciao.

Giuseppe

0 Karma

aasabatini
Motivator

Hi @uagraw01 

 

you can run this search directly on the HF

| rest splunk_server=local /services/apps/local | search update.version=* | table title version update.version

 

or you can run this search on the search head but you need to specify the hf server

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

uagraw01
Builder

@aasabatini From the search head it is not working while i am mentioning any hf name.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01.,

please try this:

| rest /services/apps/local
| table label version disabled

Ciao.

Giuseppe

uagraw01
Builder

@gcusello but how to check in which heavy forwarder which add-ons are installed and what is the current add-on version

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

hi @uagraw01,

sorry I forgot to say that you have to run this search on each Heavy Forwarder or add splunk_server:

| rest /services/apps/local splunk_server=<hostname>
| table label version disabled

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01,

sorry I forgot that this option is only for search peers.

You can run that search only on the Heavy Forwarders.

You could eventually schedula that search saving results in a csv file (with outputcsv command at the end) and then read that file and send it to Splunk using a file input.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If/when (you really should) have a MC you could add all HFs as peers to it and create separate groups for those. Then you could use @gcusello ‘s rest query with splunk_server=<your group name here> To get this information from one place.

There is already idea for separate role for HFs / intermediate gateway forwarders in ideas.splunk.com, which could work better than add those as peers.

r. Ismo

uagraw01
Builder

@gcusello Yes i think i have to put this command on every heavy forwarder individually because we are using Splunk cloud.

0 Karma

uagraw01
Builder

@gcusello The last search is not working while i am using any hostname there.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...