That's kinda what I wanted to assume to. According to Splunk, the following query is what tells me if the app is successfully installed: index=_internal source=*metrics.log group=tcpout_connections name=splunkcloud*
| stats latest(_time) AS _time latest(name) AS name by host
| rex field=name "(?<output_group>.+?)\:"
| eval fwd_config=if(output_group="splunkcloud","legacy","new")
| stats count by _time host output_group fwd_config
| reltime
| fields _time reltime host output_group fwd_config
| sort 0 fwd_config If that 'fwd_config' field says 'new', it was successful. Instances that need the update are marked 'legacy'. When I try to unpack manually and restart Splunk; it still shows up as 'legacy' afterward. When i do the update via their process, it is marked as 'new'. Thank you for the help by the way, you have been amazing thus far
... View more