All Apps and Add-ons

Add-on Not Visible After Splunk Upgrade (10.1 → 10.2)

Jayaraman
Explorer

I have a custom Splunk add-on that was developed and tested on Splunk Enterprise 10.1. It was functioning correctly and visible in the Apps list.

After upgrading Splunk to version 10.2, the add-on is no longer visible in the UI. The installation completes without errors, but the app does not appear under Apps.

I would like clarification on the following:

  1. Are there any changes introduced in Splunk 10.2 that could cause an add-on to be hidden after upgrade?

  2. Can settings like max_version in app.conf prevent the add-on from loading in newer versions?

  3. Does Splunk 10.2 enforce new AppInspect or validation checks that could automatically disable an app?

  4. What logs should I check to identify why the add-on is not appearing?

  5. What is the recommended best practice to ensure an add-on remains compatible across future Splunk Enterprise upgrades?

The add-on uses standard configuration files and modular inputs (no unsupported APIs).

Any guidance on maintaining compatibility across minor Splunk upgrades would be appreciated.

Labels (1)
Tags (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Jayaraman 

There is nothing that I can think of that would stop an app being visible following an upgrade, even if there was an issue with something like python version you would still see the app.

Can you confirm the app exists in $SPLUNK_HOME/etc/apps/<appID> ?

Do the permissions match the user that runs Splunk as? And matches the other apps?

To clarify, there was no 10.1.x for Splunk Enterprise (Cloud only) - I assume you came from 10.0.x to 10.2.0 ?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...