Splunk Search
Highlighted

What search query can I use on my search head to list all forwarder hosts and their associated Splunk forwarder versions?

Path Finder

Greetings

Is there a query that I can use on my search head to list all my forwarder hosts and their associated splunk forwarder versions

Highlighted

Re: What search query can I use on my search head to list all forwarder hosts and their associated Splunk forwarder versions?

SplunkTrust
SplunkTrust

This is part of what the SoS app uses to update its forwarders lookup file:

  index=_internal source=*metrics.log* group=tcpin_connections | regex hostname!="\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}" | eval sos_server=hostname | stats latest(build) AS build latest(arch) AS cpu_arch latest(fwdType) AS forwarder_type latest(os) AS os_name latest(version) AS version by sos_server

https://apps.splunk.com/app/748/

View solution in original post

Highlighted

Re: What search query can I use on my search head to list all forwarder hosts and their associated Splunk forwarder versions?

Path Finder

Many thanks. That worked

0 Karma
Highlighted

Re: What search query can I use on my search head to list all forwarder hosts and their associated Splunk forwarder versions?

Builder

If you can't do SoS, then here's a simple search against the _internal index that works for me;

index=_internal sourcetype=splunkd version source=*metrics.log | table hostname os version build

Highlighted

Re: What search query can I use on my search head to list all forwarder hosts and their associated Splunk forwarder versions?

Explorer

I think this is what you are looking for:

index=_internal sourcetype=splunkd destPort!="-"| stats sparkline count by hostname, sourceHost, host, destPort, version | rename destPort as "Destination Port" | rename host as "Indexer" | rename sourceHost as "Forwarder IP" | rename version as "Splunk Forwarder Version" | rename hostname as "Forwarder Host Name" | rename sparkline as "Traffic Frequency" | sort - count

Highlighted

Re: What search query can I use on my search head to list all forwarder hosts and their associated Splunk forwarder versions?

SplunkTrust
SplunkTrust

I used your solution to solve my question here.. Thanks for posting this!

https://answers.splunk.com/answers/379013/alert-if-a-forwarder-service-stops.html