All Apps and Add-ons

How does version change/upgrade affect Splunk Apps And Add-on configuration file in distributed Environment. ?

pratapbhanu2047
Engager

I am new to splunk and trying to find answer to question. I would really appreciate if you could guide me to good documentation or Link.

Tags (2)
0 Karma
1 Solution

tmarlette
Motivator

In short, everything in /opt/splunk/etc/system/default and if it's an app / add-on, anything in /opt/splunk/etc/apps/<app_name>/default is changed or adjusted. This is the primary reason for making any customizations in the /local directory in either an app, or the CORE component. (This is assuming a non clustered deployment)

if you make changes in a /default directory, they will be overwritten on upgrade.

View solution in original post

tmarlette
Motivator

In short, everything in /opt/splunk/etc/system/default and if it's an app / add-on, anything in /opt/splunk/etc/apps/<app_name>/default is changed or adjusted. This is the primary reason for making any customizations in the /local directory in either an app, or the CORE component. (This is assuming a non clustered deployment)

if you make changes in a /default directory, they will be overwritten on upgrade.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...