I'm looking for a search to pull the OS distribution of all hosts in an AWS environment, along with their version. Purpose is to get a snapshot from across an environment with 400+ hosts with what is within.
Even though I know I would need to edit, I started off using a base search of:
index=_internal fwdType="*" | dedup hostname | stats count by os, version
But that doesn't get to what I'm looking for which would be a count to say
Linux CentOS 5.5 10 hosts
Linux Ubuntu 6 8 hosts
index=_internal is related to the Splunk version and not related to the OS version. You would need to use the
Windows App https://splunkbase.splunk.com/app/1680/ or the
*unix App https://splunkbase.splunk.com/app/273/ or any other script / WMI to get the OS version.