SA - Splunk UF Upgrade Monitoring for Windows app icon

SA - Splunk UF Upgrade Monitoring for Windows

Provides dashboards, data model support, reporting, and troubleshooting views for Windows Universal Forwarder upgrade activity generated by the companion Windows UF upgrade automation TA .

splunk product badge

Latest Version 1.0.0
June 1, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0, 7.3, 7.2, 7.1, 7.0
Rating

0

(0)

Log in to rate this app
Support
SA - Splunk UF Upgrade Monitoring for Windows support icon
Developer Supported app
SA - Splunk UF Upgrade Monitoring for Windows is a Search Head app that provides dashboards, reporting views, data model support, event code visibility, and troubleshooting workflows for Windows Universal Forwarder upgrade activity. This app is designed to help Splunk administrators monitor upgrade outcomes across Windows Universal Forwarders, identify hosts that successfully upgraded, find hosts that failed or remain below the target version, and investigate setup, scheduled task, service control, MSI, cleanup, state tracking, and retry-control events. This Search Head app does not perform endpoint upgrades directly. Upgrade execution is handled by the companion endpoint automation TA, `TA-windows_uf_upgrade_automation`. Parsing and indexing support is handled by the companion parsing TA, `TA-windows_uf_upgrade_parsing`. While this Search Head app is not required to execute Windows Universal Forwarder upgrades, it is recommended for operational visibility, troubleshooting, and reporting. It helps administrators understand what happened during an upgrade rollout and which endpoints may need remediation. The app provides visibility into events such as: * Upgrade attempts * Successful upgrades * Failed upgrades * Hosts not on the target version * Version validation results * Scheduled task creation and execution * Splunk service stop/start activity * MSI installer results * Installer cleanup activity * JSON state tracking * Retry-loop prevention * Controlled force retry and retry reset activity This app is intended for Splunk Enterprise Search Heads or Search Head Clusters. It should not be deployed to Windows Universal Forwarders as the upgrade execution component.

Categories

IT Operations

Created By

Joshua Johnson

Type

app

Downloads

5

Resources

Log in to report this app listing