Splunk® Enterprise

Troubleshooting Manual

Download manual as PDF

Splunk version 4.x reached its End of Life on October 1, 2013. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Determine which version of Splunk you're running

In Splunk Web

Every page title in Splunk Web includes the version and build numbers. You can also click on the About link at the top right of most pages to view a JavaScript overlay with the version and build numbers.


At the command line

Use one minus or two minuses; Splunk gets it either way:

> ./splunk --version
Splunk 4.2.3 (build 105368)


> ./splunk -version
Splunk 4.2.3 (build 105368)

From the files

You can get the version information from the file $SPLUNK_HOME/etc/splunk.version

> cat $SPLUNK_HOME/etc/splunk.version 

In Splunk Search

Starting with version 4.0.10, Splunk indexes the splunk.version file into the _internal index and sends it along to the indexer by forwarders.

Here's a search that shows you how many installs you have of each Splunk version:

index=_internal sourcetype=splunk_version | dedup host | top VERSION

Introduction to troubleshooting Splunk Enterprise
Use btool to troubleshoot configurations

This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7, 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters