Splunk Search

How to find total distribution of Universal forwarders in Splunk based on operating system types?

OMohi
Path Finder

I would like to know how do I find the distribution of all Universal forwarders in Splunk by os type (Unix, Windows, etc).

Is there a query that'll define this allocation.

Tags (4)
0 Karma

joshua_hart1
Path Finder

index=_internal fwdType="*" | dedup hostname | stats count by os, version

alacercogitatus
SplunkTrust
SplunkTrust

OMohi,

Install the Deployment Monitor App on your deployment server.

http://splunk-base.splunk.com/apps/67836/splunk-deployment-monitor

There is a dashboard there with the information.

bandit
Motivator

Hoping that either Deployment Monitor or Forwarder Managment would add a simple export option to a csv. Then it would be much easier to use the export to build a serverclass.conf without having to first write your own query in Splunk.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

If this answered your question - please accept it. Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...