Hello Splunk Community.
I am trying to use Splunk to search for the serial number of the installed hard drive(s).
When I run a search for a particular computer, is there a field that gets populated that will have the hard drive serial numbers? To complicate the issue, I'm looking at servers as well as workstations, most of which have multiple hard drives installed. Is there a better way to get the information?
We are using Splunk Enterprise v8.2.2
That's not something you'll get from out-of-the-box Splunk. While Splunk will know about servers from the data sent in normally, identifying the components within a server is another matter that usually requires a specialized scanner utility.