<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between different options for app update in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698428#M20178</link>
    <description>&lt;P&gt;Adding to what &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; already said - remember than some options might simply be not available in specific situations. Many Splunk components will actually run without web interface enabled so in those cases you will obviously not be able to use it for upgrade. If your environment grows and you step into the clustering grounds the only way of installing apps (including upgrading) will be using clustering mechanisms (either pushing from deployer or cluster manager). Even with small-scale installation you can use deployment server to serve apps to your Splunk components. And that's actually a typical Splunk way of automating app install/upgrade.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Sep 2024 20:12:40 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-09-06T20:12:40Z</dc:date>
    <item>
      <title>Difference between different options for app update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698276#M20164</link>
      <description>&lt;P&gt;Hello Splunkees,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what are the differences between the&amp;nbsp;different options for app updates? I know 3 diffentent ways to update an app:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Via webinterface: Apps -&amp;gt; Manage Apps -&amp;gt; Install app from file -&amp;gt; Check '&lt;SPAN&gt;Upgrade app. Checking this will overwrite the app if it already exists.'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) Via CLI:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;./splunk install app &amp;lt;app_package_filename&amp;gt; -update 1 -auth &amp;lt;username&amp;gt;:&amp;lt;password&amp;gt;&lt;/PRE&gt;&lt;P&gt;3) Extract the content of the app.tgz to $SPLUNK_HOME/etc/apps/ (if app already exists, override files) and after that restart splunk service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Background of my question: I want to implement an automated app update process with ansible for our environment and I want to use the smartest method. Currently, we're using Splunk 9.1.5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;dschwarz&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 10:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698276#M20164</guid>
      <dc:creator>dschwarz</dc:creator>
      <dc:date>2024-09-05T10:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between different options for app update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698409#M20174</link>
      <description>&lt;P&gt;The biggest difference is #3 requires a restart of Splunk before the app can be used.&amp;nbsp; For the other methods, a restart may be needed (depending on what is changed), but may not be required.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 15:37:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698409#M20174</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-09-06T15:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between different options for app update</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698428#M20178</link>
      <description>&lt;P&gt;Adding to what &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; already said - remember than some options might simply be not available in specific situations. Many Splunk components will actually run without web interface enabled so in those cases you will obviously not be able to use it for upgrade. If your environment grows and you step into the clustering grounds the only way of installing apps (including upgrading) will be using clustering mechanisms (either pushing from deployer or cluster manager). Even with small-scale installation you can use deployment server to serve apps to your Splunk components. And that's actually a typical Splunk way of automating app install/upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 20:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Difference-between-different-options-for-app-update/m-p/698428#M20178</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-06T20:12:40Z</dc:date>
    </item>
  </channel>
</rss>

