Splunk Search

How to find the User ID that was used for the original splunk installation

jlongworth
Explorer

I want to upgrade a system. How do I find the ID for the user that installed it? Is it somewhere in the system?

Tags (1)
0 Karma

PavelP
Motivator

Hello @jlongworth

you can find this information in the operating system's logs:

  • Windows - eventvwr.msc - installation
  • Linux - find the installation date and time in /var/log/yum*log or /var/log/dpgk*log and correlate it with output of last command

you can find it using splunk UI if these logs are indexed by splunk

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...