Splunk Search

Improve query to list apps and versions on all indexer nodes

radam2000
Path Finder

I have this query to list the apps and their versions last update date for apps on all index nodes, however the updated date lists a default for all apps as "1969-12-31T19:00:00-05:00". Anyway to modify this to produce the proper updated date?

| rest /services/apps/local | search disabled=* |table splunk_server, title, label, version, updated, disabled, visible, description, author, configured, core, "eai:acl.app", "eai:acl.sharing", id

thanks in advance for any assistance...

Rich

Tags (1)
0 Karma

radam2000
Path Finder

It does not provide a correct update date for any entry - note output of query does show disabled field which contains both entries with 0 and 1 for true and false annd update date is the same

Thanks for your reply
Rich

0 Karma

DalJeanis
Legend

Does it list the correct updated date/time for apps that are not disabled?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...