<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579793#M25136</link>
    <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Where can I disable the default Bucket Copy Trigger search to prevent jar files from returning in Splunk? Also, which splunk instance does this search need to be disabled? Please see below:&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Jar files matching the same filename of the files found in the directories above, but found in other directories on your Splunk instances are likely from normal Splunk operation (e.g. search head bundle replication) and can be safely deleted. If any jar files return in the splunk_archiver app, disabling the default Bucket Copy Trigger search in that app will stop this behavior from happening. "&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My Splunk architecture (airgapped) includes the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Search Head&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Heavy Forward&lt;/P&gt;&lt;P&gt;1 Deployment Server&lt;/P&gt;&lt;P&gt;1 Cluster Master/License Master (operating as the same instance)&lt;/P&gt;&lt;P&gt;7 Indexers (all clustered)&lt;/P&gt;&lt;P&gt;Within my distributed environment, just want to know where to disable this search to prevent this from happening again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-KB&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jan 2022 15:11:59 GMT</pubDate>
    <dc:creator>KayBeesKnees83</dc:creator>
    <dc:date>2022-01-03T15:11:59Z</dc:date>
    <item>
      <title>Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579793#M25136</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Where can I disable the default Bucket Copy Trigger search to prevent jar files from returning in Splunk? Also, which splunk instance does this search need to be disabled? Please see below:&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Jar files matching the same filename of the files found in the directories above, but found in other directories on your Splunk instances are likely from normal Splunk operation (e.g. search head bundle replication) and can be safely deleted. If any jar files return in the splunk_archiver app, disabling the default Bucket Copy Trigger search in that app will stop this behavior from happening. "&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My Splunk architecture (airgapped) includes the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Search Head&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 Heavy Forward&lt;/P&gt;&lt;P&gt;1 Deployment Server&lt;/P&gt;&lt;P&gt;1 Cluster Master/License Master (operating as the same instance)&lt;/P&gt;&lt;P&gt;7 Indexers (all clustered)&lt;/P&gt;&lt;P&gt;Within my distributed environment, just want to know where to disable this search to prevent this from happening again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-KB&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 15:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579793#M25136</guid>
      <dc:creator>KayBeesKnees83</dc:creator>
      <dc:date>2022-01-03T15:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579833#M25137</link>
      <description>&lt;P&gt;The search will definitely run on the search head so disable it there.&lt;BR /&gt;You can see the search in the audit index and additionally in the remote_ searches log on the indexers.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I don't believe the cluster master or indexers trigger this but it is safe to disable it. It related to hadoop data roll functionality&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 07:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579833#M25137</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2022-01-04T07:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579872#M25138</link>
      <description>&lt;P&gt;Hi gjanders,&lt;/P&gt;&lt;P&gt;Thank you for&amp;nbsp; your reply and the information you provided. How do I disable this functionality/search in the Search Head? Specifically, is there a conf.file to disable or is there another way to disable the search?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-KB&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 13:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579872#M25138</guid>
      <dc:creator>KayBeesKnees83</dc:creator>
      <dc:date>2022-01-04T13:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579922#M25140</link>
      <description>&lt;P&gt;I don't have access to a Linux Splunk instance to test right now, but it should either be a "archive buckets" or "archive buckets trigger" saved search.&lt;BR /&gt;&lt;BR /&gt;You can disable it via the Settings -&amp;gt; saved searches, or by creating a savedsearches.conf with the stanza and setting disabled=1&lt;/P&gt;&lt;P&gt;Or you could disable the entire app, I would disable the app personally...&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 22:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579922#M25140</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2022-01-04T22:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579923#M25141</link>
      <description>&lt;P&gt;With that said the | archivebuckets command might still work with the savedsearch disabled, it should fail once the app is disabled...&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 22:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/579923#M25141</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2022-01-04T22:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583979#M25240</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223990"&gt;@KayBeesKnees83&lt;/a&gt;&amp;nbsp; - please let me know how did you finally disabled the "Bucket trigger" in savedsearch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which savedsearch.conf file was used .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am suffering from the issue and looking for the correct way to disable this setting .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 17:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583979#M25240</guid>
      <dc:creator>rashiagrawal</dc:creator>
      <dc:date>2022-02-07T17:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583981#M25241</link>
      <description>&lt;P&gt;I upgraded to Splunk v8.2.4 and deleted all the files as listed in the "Log4j report" from Splunk. However, if the aforementioned do not resolve your issue. You can disable the app completely. Search for the app "Bucket Copy" and just disable the app.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-KB&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 17:21:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583981#M25241</guid>
      <dc:creator>KayBeesKnees83</dc:creator>
      <dc:date>2022-02-07T17:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583984#M25242</link>
      <description>&lt;P&gt;Is there app named "Bucket copy" or "splunk_archiver".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 17:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583984#M25242</guid>
      <dc:creator>rashiagrawal</dc:creator>
      <dc:date>2022-02-07T17:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583990#M25243</link>
      <description>&lt;P&gt;It is the "splunk_archiver" -- the Bucket Copy Trigger search is located within that app.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 17:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583990#M25243</guid>
      <dc:creator>KayBeesKnees83</dc:creator>
      <dc:date>2022-02-07T17:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583991#M25244</link>
      <description>&lt;P&gt;Thank you. I have found the app on search head and disabled it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 17:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/583991#M25244</guid>
      <dc:creator>rashiagrawal</dc:creator>
      <dc:date>2022-02-07T17:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587516#M25316</link>
      <description>&lt;P&gt;Isn't the bucket copy functionality necessary in Splunk?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 18:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587516#M25316</guid>
      <dc:creator>diptij</dc:creator>
      <dc:date>2022-03-03T18:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587518#M25317</link>
      <description>&lt;P&gt;No, it is not a necessary functionality in Splunk.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 18:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587518#M25317</guid>
      <dc:creator>KayBeesKnees83</dc:creator>
      <dc:date>2022-03-03T18:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587521#M25319</link>
      <description>&lt;P&gt;So [Bucket Copy Trigger] actually calls archivebuckets, which calls copybuckets.&amp;nbsp; The archiving was leading me to question if the functionality is necessary because buckets do get moved from hot, warm, cold, archive.&lt;/P&gt;&lt;P&gt;In any splunk install (head or indexer) I just need to do the following:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; copy&amp;nbsp; $SPLUNK_HOME/etc/apps/splunk_archiver/&lt;STRONG&gt;default&lt;/STRONG&gt;/savedsearches.conf to $SPLUNK_HOME/etc/aps/splunk_archiver/&lt;STRONG&gt;local&lt;/STRONG&gt;/savedsearches.conf&lt;/P&gt;&lt;P&gt;2. Update &lt;STRONG&gt;local/savedsearches.conf&lt;/STRONG&gt; so under &lt;STRONG&gt;[Bucket Copy Trigger]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;change &lt;STRONG&gt;enableSched = 1&lt;/STRONG&gt; to&amp;nbsp; &lt;STRONG&gt;enableSched = 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Anything else?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 19:28:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587521#M25319</guid>
      <dc:creator>diptij</dc:creator>
      <dc:date>2022-03-03T19:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587522#M25320</link>
      <description>&lt;P&gt;Looks good. I would also restart splunkd for good measure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 19:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587522#M25320</guid>
      <dc:creator>KayBeesKnees83</dc:creator>
      <dc:date>2022-03-03T19:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Removing Log4j Version 2 from Splunk Enterprise - Disabling the default Bucket Copy Trigger</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587539#M25321</link>
      <description>&lt;P&gt;It ends up that in the &lt;STRONG&gt;local/savedsearches.conf&lt;/STRONG&gt; you have to also add &lt;STRONG&gt;disabled=1&lt;/STRONG&gt; also&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 22:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Removing-Log4j-Version-2-from-Splunk-Enterprise-Disabling-the/m-p/587539#M25321</guid>
      <dc:creator>diptij</dc:creator>
      <dc:date>2022-03-03T22:31:01Z</dc:date>
    </item>
  </channel>
</rss>

