Splunk Search

Is there a way to determine the install date for Splunk universal forwarders?


We are using SCCM to install Splunk Universal Forwarder in our organization and via our Deployment server, I can keep track of when the UF is installed on endpoints.

Is there a way via a search or using the REST API to see what the install date is for each UF?
Being that we're doing a rolling install I'd like to keep track of which date the UF was installed on each endpoint.


Path Finder

Found a similar question to yours. Please check if this applies to your scenario. https://answers.splunk.com/answers/137728/is-there-any-meta-data-that-identifies-when-a-splunk-agent...

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!