All Apps and Add-ons

How would you update customized app in clustered environment?

splunkreal
Motivator

Hello,

would you copy the app's full folder in another location as backup, extract new app from tgz in master-apps or shcluster/apps then copy your local folder from backup to new one?

Thanks.

* If this helps, please upvote or accept solution 🙂 *
Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal,

Updates must always be done by Master Node (on indexers' Cluster)  and on Deployer (on Search' Heads Cluster).

the update process is usually descripted in documentation, but anyway is simple:

  • copy app on Master Node or Deployer,
  • untar it in the correct folder,
  • check files ownership (splunk:splunk),
  • push it using the commands (GUI from Master Node and command from Deployer.

beware when you update an App from Deployer to preserve lookups because you risk to override the existing ones!

Ciao.

Giuseppe

0 Karma

splunkreal
Motivator

Hi @gcusello 

so you don't mind if old files/deprecated, in default for instance, remain for new app?

Thanks.

 

* If this helps, please upvote or accept solution 🙂 *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal,

when you update an app with a new version all the conf files in default will be overrided, only the ones in local will be saved.

Ciao.

Giuseppe

0 Karma

splunkreal
Motivator

Thanks @gcusello however what about no longer in use confs or files no longer in use? Which command do you use to untar?

 

* If this helps, please upvote or accept solution 🙂 *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkreal,

if I correctly understood, you're speking of update apps: new app versions contains only correct conf files and deprecated ones aren't still in the app.

Ciao.

Giuseppe

0 Karma

splunkreal
Motivator

For example we downloaded app from splunkbase.

We have done some local confs.

We want to get the latest one from splunkbase

if we untar new app into old app directory then we may see old remaining files which were used by old app but not in the new app?

Thanks for your time 🙂

* If this helps, please upvote or accept solution 🙂 *
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...