<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reinstalling Splunk in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Reinstalling-Splunk/m-p/690754#M13977</link>
    <description>&lt;P&gt;I have been working on our Splunk Dev environment, and since then, I have reinstalled and uninstalled Splunk many times. I had a question as to why even on a fresh install, the apps, and a few other artifacts remain? Once i wipe all traces of splunk off a server, I would think that upon reinstall, it would be a fresh start. yet, some of the GUI settings remain, and even some apps on the specific servers remain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one dev indexer, SH, and Forwarder. We have specific apps that i have installed for people months ago, and since then, have rm -rf all traces that I could find of splunk, and yet, upon reinstall of splunk, I still see those apps under /SPLUNK_HOME/etc/apps. I have the same tar that i am unzipping on each server. yet, things like that persist across the servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, what is storing that info? For example, the app&amp;nbsp;&lt;EM&gt;BeyondTrust-PMCloud-Integration/&lt;/EM&gt;, located under &lt;EM&gt;/export/opt/splunk/etc/apps&lt;/EM&gt;,&amp;nbsp;persists throughout two or three reinstalls of splunk. Is the FS storing data about the Splunk install even after i rm -rf all of /export/opt/splunk?&amp;nbsp;&amp;nbsp;Im trying to fix some annoying issues for replication and such by just resetting the servers, since i am building them from ground up, but these servers are still retaining some stuff. I decided to redo Splunk dev after we kept having issues with the old Dev environment. I was wanting a completely fresh start, but it seems as if Splunk retains some things even after a full reset. So im not sure if some problems are still persisting because something from a previous install is still floating around somewhere. Thanks for any help&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2024 19:57:22 GMT</pubDate>
    <dc:creator>Abass42</dc:creator>
    <dc:date>2024-06-14T19:57:22Z</dc:date>
    <item>
      <title>Reinstalling Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Reinstalling-Splunk/m-p/690754#M13977</link>
      <description>&lt;P&gt;I have been working on our Splunk Dev environment, and since then, I have reinstalled and uninstalled Splunk many times. I had a question as to why even on a fresh install, the apps, and a few other artifacts remain? Once i wipe all traces of splunk off a server, I would think that upon reinstall, it would be a fresh start. yet, some of the GUI settings remain, and even some apps on the specific servers remain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one dev indexer, SH, and Forwarder. We have specific apps that i have installed for people months ago, and since then, have rm -rf all traces that I could find of splunk, and yet, upon reinstall of splunk, I still see those apps under /SPLUNK_HOME/etc/apps. I have the same tar that i am unzipping on each server. yet, things like that persist across the servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, what is storing that info? For example, the app&amp;nbsp;&lt;EM&gt;BeyondTrust-PMCloud-Integration/&lt;/EM&gt;, located under &lt;EM&gt;/export/opt/splunk/etc/apps&lt;/EM&gt;,&amp;nbsp;persists throughout two or three reinstalls of splunk. Is the FS storing data about the Splunk install even after i rm -rf all of /export/opt/splunk?&amp;nbsp;&amp;nbsp;Im trying to fix some annoying issues for replication and such by just resetting the servers, since i am building them from ground up, but these servers are still retaining some stuff. I decided to redo Splunk dev after we kept having issues with the old Dev environment. I was wanting a completely fresh start, but it seems as if Splunk retains some things even after a full reset. So im not sure if some problems are still persisting because something from a previous install is still floating around somewhere. Thanks for any help&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 19:57:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Reinstalling-Splunk/m-p/690754#M13977</guid>
      <dc:creator>Abass42</dc:creator>
      <dc:date>2024-06-14T19:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Reinstalling Splunk</title>
      <link>https://community.splunk.com/t5/Installation/Reinstalling-Splunk/m-p/690777#M13978</link>
      <description>&lt;P&gt;Everything Splunk knows about itself is in $SPLUNK_HOME (/export/opt/splunk, in this case).&amp;nbsp; Once that directory is wiped, there will be no remnants of Splunk software on the system.&amp;nbsp; Indexed data may remain, especially if $SPLUNK_DB is in a different mount point (as recommended).&lt;/P&gt;&lt;P&gt;Before re-installing Splunk, did you confirm the app directories are gone?&amp;nbsp; Have you looked to see if they're part of the tarball you're expanding?&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 00:22:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Reinstalling-Splunk/m-p/690777#M13978</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-15T00:22:09Z</dc:date>
    </item>
  </channel>
</rss>

