Splunk Search

How to disable Splunk app using deployment server?

tbavarva
Path Finder

Hi all,

I have deployed an app using a deployment server in Splunk.

Suppose I got a new update for that app and I need to upgrade it.

I have below search:

  1. Since I am using deployment server to push the update on deployment clients, how can I take back up of that app installed on a specific client (I assume it would help me in recover an old app if anything goes wrong)? Will below command help me for this point?
    /opt/splunk/bin/splunk disable app -auth Username:Password

  2. "disabled-apps" folder will help me to revert the changes in any case?

Thanks in advance.

Regards,
Tejas

0 Karma
1 Solution

FrankVl
Ultra Champion

Before starting the update, the app on the client is the same as the app on the deployment server, right?

So just take a backup of the app on the deployment server before you replace the app with the new version. And then the clients will pull the update. In case of any issues, restore backup on deployment server and the clients will pull the old version again.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Before starting the update, the app on the client is the same as the app on the deployment server, right?

So just take a backup of the app on the deployment server before you replace the app with the new version. And then the clients will pull the update. In case of any issues, restore backup on deployment server and the clients will pull the old version again.

0 Karma

tbavarva
Path Finder

Thanks a lot Frank 🙂 and other folks Vijeta and paramagurukarthikeyan for your answers.

0 Karma

tbavarva
Path Finder

Adding more on this:

Can we disable or take back up of any app from deployment server? If yes, how?

Regards,
Tejas

0 Karma

paramagurukarth
Builder

In deployment server, Edit the app.conf and change the state manually.. and restart to push the modified
[install]
state=disabled

0 Karma

Vijeta
Influencer

@tbavarva - You can copy the particular app folder from /opt/splunk/etc/apps/ from your deployment client to take back-up.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...