All Apps and Add-ons

What is the default behavior for an app that does not have an app.conf file?

Simeon
Splunk Employee
Splunk Employee

If I have a Splunk App that does not contain an app.conf file, what is the default behavior? I'm trying to figure out if my app is turned on or off.

Tags (1)
1 Solution

the_wolverine
Champion

I think it is important to mention versions here.

In 4.x, we have app.conf

In version 3.x we have the MANIFEST file.

When migrating from 3.x to 4.x there is no app.conf created during migration. Thus, we have the undesired behavior of all apps from version 3.x disabled via MANIFEST file are now enabled after migration to 4.x

View solution in original post

the_wolverine
Champion

I think it is important to mention versions here.

In 4.x, we have app.conf

In version 3.x we have the MANIFEST file.

When migrating from 3.x to 4.x there is no app.conf created during migration. Thus, we have the undesired behavior of all apps from version 3.x disabled via MANIFEST file are now enabled after migration to 4.x

gkanapathy
Splunk Employee
Splunk Employee

sounds like a migration bug.

0 Karma

jrodman
Splunk Employee
Splunk Employee

In keeping with historial behavior, apps with no app.conf anywhere are enabled.

matt
Splunk Employee
Splunk Employee

If you are doing anything that is non-trivial you are going to need this file, since it is what the UI needs for showing labels and configs. Without it I believe it would just be a container of confs. Depending on what you define in your metadata/default.meta it is likely that the confs will not be accessible by other apps so you'll have a hard time taking advantage of anything you put in it.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...