All Apps and Add-ons

How does version change/upgrade affect Splunk Apps And Add-on configuration file in distributed Environment. ?

pratapbhanu2047
Engager

I am new to splunk and trying to find answer to question. I would really appreciate if you could guide me to good documentation or Link.

Tags (2)
0 Karma
1 Solution

tmarlette
Motivator

In short, everything in /opt/splunk/etc/system/default and if it's an app / add-on, anything in /opt/splunk/etc/apps/<app_name>/default is changed or adjusted. This is the primary reason for making any customizations in the /local directory in either an app, or the CORE component. (This is assuming a non clustered deployment)

if you make changes in a /default directory, they will be overwritten on upgrade.

View solution in original post

tmarlette
Motivator

In short, everything in /opt/splunk/etc/system/default and if it's an app / add-on, anything in /opt/splunk/etc/apps/<app_name>/default is changed or adjusted. This is the primary reason for making any customizations in the /local directory in either an app, or the CORE component. (This is assuming a non clustered deployment)

if you make changes in a /default directory, they will be overwritten on upgrade.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...