Splunk Search

Is there a way to determine the install date for Splunk universal forwarders?

jwalzerpitt
Influencer

We are using SCCM to install Splunk Universal Forwarder in our organization and via our Deployment server, I can keep track of when the UF is installed on endpoints.

Is there a way via a search or using the REST API to see what the install date is for each UF?
Being that we're doing a rolling install I'd like to keep track of which date the UF was installed on each endpoint.

Thx

KARANMALHOTRA
Path Finder

Found a similar question to yours. Please check if this applies to your scenario. https://answers.splunk.com/answers/137728/is-there-any-meta-data-that-identifies-when-a-splunk-agent...

Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...