Splunk Enterprise

How to write a Splunk query to find the Splunk UF version for specific set of hosts in Splunk Enterprise

Hemnaath
Motivator

Hi Team,

I wanted to wirte query to find the Splunk agent version of specific set of hosts in our environment, I had tired the below link to find out version detail for all UF uisng the below link.

https://community.splunk.com/t5/Getting-Data-In/How-can-I-find-a-listing-of-all-universal-forwarders...

But I am unable to segregate to specific set of hosts.  So could anyone let me know how to wirte a query to fetch the version details.

 

Thanks in Advance. 

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console will do that, if you have forwarder monitoring enabled.  Go to Forwarders->Forwarders:Deployment in the MC.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Hemnaath
Motivator

thanks for your time,  Yes I know that we can find that from Splunk Monitoring console,  but is there a way to write a query which can be used to fetch specific set of host agent version from search head.

thanks in advance.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Grab the query from the MC and put it on the SH of choice.  Modify it as desired.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...