JoeIII - thanks for this, it was just what I needed to search for forwarders that needed to be upgraded. Just one typo - sourceIP should be sourceIp:
index=_internal source=*metrics.log group=tcpin_connections | eval sourceHost=if(isnull(hostname), sourceHost,hostname) | dedup sourceHost | table sourceHost sourceIp os version | sort version
... View more