Splunk Search

How to find the User ID that was used for the original splunk installation

jlongworth
Explorer

I want to upgrade a system. How do I find the ID for the user that installed it? Is it somewhere in the system?

Tags (1)
0 Karma

PavelP
Motivator

Hello @jlongworth

you can find this information in the operating system's logs:

  • Windows - eventvwr.msc - installation
  • Linux - find the installation date and time in /var/log/yum*log or /var/log/dpgk*log and correlate it with output of last command

you can find it using splunk UI if these logs are indexed by splunk

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...