Splunk Search

Deployed Apps Search

jason_hotchkiss
Communicator

I would like to determine how many times an app on a deployment server has been deployed.  I'm not concerned with the host information.  I'm trying to determine which Apps are no longer being used and can be archived.  I suspect it would come from the | rest command.

| rest splunk_server=127.0.0.1 /services/deployment/server/clients

I'm just not sure which fields and how to accurately calculate this. Looking for suggestions.

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That information may be in the Deployment Server's logs.  Look for "DS" in the messages (I don't have access to a DS to check).

Be aware, however, that lack of downloads does not mean the app is not used.  It's possible the app hasn't changed in a while so no clients have needed to download it.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...