I am trying to determine the version of all my Splunk indexers and search heads centrally.
I read here
http://docs.splunk.com/Documentation/Splunk/5.0.2/Troubleshooting/CheckSplunkversion
that splunk is supposed to log the contents of splunk.version which would be perfect
I am trying the search that is provided but I am not getting any results
index=_internal sourcetype=splunk_version | dedup host | top VERSION
ran that for all time, i performed an upgrade last week so there should be data from that file.
where can I find that information so that I can display it in a dashboard for easy reporting ?
Use the following search from your search-head:
| rest /services/server/info | table splunk_server version