Installation

How to remove/uninstall an app

Roy_9
Motivator

Hello,

We have few apps that are no longer needed in our on premise environment. We maintain git repo for configs.

Can anyone please help me with the steps to uninstall/remove the app.

 

 

Thanks

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The procedure varies depending on the environment.

In a standalone server or independent search heads, indexers, and heavy forwarders, just remove the app directory from $SPLUNK_HOME/etc/apps and restart Splunk.

In a search head cluster, remove the app from $SPLUNK_HOME/etc/shcluster on the SHC Deployer and push the shbundle.

In an indexer cluster, remove the app from $SPLUNK_HOME/etc/manager-apps (or master-apps) and push the bundle.

For universal forwarders, remove the app from the appropriate server class(es).  If no clients use the app, it can be removed from $SPLUNK_HOME/etc/deployment-apps.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The procedure varies depending on the environment.

In a standalone server or independent search heads, indexers, and heavy forwarders, just remove the app directory from $SPLUNK_HOME/etc/apps and restart Splunk.

In a search head cluster, remove the app from $SPLUNK_HOME/etc/shcluster on the SHC Deployer and push the shbundle.

In an indexer cluster, remove the app from $SPLUNK_HOME/etc/manager-apps (or master-apps) and push the bundle.

For universal forwarders, remove the app from the appropriate server class(es).  If no clients use the app, it can be removed from $SPLUNK_HOME/etc/deployment-apps.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...