If you are using Deployment server to push SplunkTAstream to splunk UF
GO to Deployment server
1) Delete app from $SPLUNKHOME$/etc/deployment-apps
2) Delete corresponding app class configuration from $SPLUNKHOME/etc/system/local/serverclass.conf
3) Restart splunk
if you are using deployer to push SplunkTAstream to Splunk Search Heads
Go to Deployer
1) Delete app from $SPLUNKHOME$/etc/shcluster/apps/
2) $SPLUNKHOME/bin apply shcluster-bundle -target https://:8089 -preserve-lookups true
ah okay. Then try removing user specific directories created for that app.
$SPLUNK_HOME/bin/splunk remove app [appname] -auth <username>:<password>
Remove user-specific directories created for your app or add-on by deleting the files found here:
Thanks for the reply's, This is one tough app!
I did what sbbadri suggested, but once the app is removed and the user-specific directories are removed when Splunk is restarted, it's back again!
The Splunk Stream app is in two directories, splunkappstream and SplunkTAstream. Both must be removed to uninstall the app.