All Apps and Add-ons

Updating Splunkbase apps in Distributed Environment

wwhite12
Path Finder

When upgrading apps/add-ons in a distributed environment, is there a recommended best practice or is it similar to deploying the app initially where I can just paste the newer downloaded version from Splunkbase over the existing app and then push the new bundle to the peers to fully update the app? And also is there any scenario where a rolling restart for this wouldn’t be required?

Thanks in advance

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You have the right method for updating apps.
See $SPLUNK_HOME/etc/system/default/app.conf for which config files do not require a rolling restart. The settings are described in $SPLUNK_HOME/etc/system/README/app.conf.spec.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You have the right method for updating apps.
See $SPLUNK_HOME/etc/system/default/app.conf for which config files do not require a rolling restart. The settings are described in $SPLUNK_HOME/etc/system/README/app.conf.spec.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...