Deployment Architecture

How to package custom app in Default splunk package / executable?

ayush1906
Path Finder

Hi folks,

I have a requirement to add custom app in the default splunk executable.

Currently, we are having splunk .tar setup after which we untar it to install and when splunk service starts we place our custom application in the "etc/apps" folder.

I was thinking is it possible that if I untar the setup file, place my app in the "etc/apps" folder and again zip it. following which I give it for deployment so that it's a one-step.

Is it possible or would it result in some hash mismatch since the original setup is getting tempered with?

0 Karma

nickhills
Ultra Champion

Is this Splunk Core or Universal Forwarder?
I cant help but think this is not the correct approach, is there a specific reason you can not use a deployment server?

If my comment helps, please give it a thumbs up!
0 Karma

ayush1906
Path Finder

hi nick, we were planning on modifying splunk core package, but we have dropped that plan due to too many unknowns.

0 Karma

ayush1906
Path Finder

splunk enterprise on a Linux server. this installation will act as a search head

0 Karma

nickhills
Ultra Champion

Why cant you use a deployment server?

You can script your install process to automatically add the host to a DS on install, and then use the DS to automatically deploy your custom application. By far and away, this is the better approach.

In my opinion, it is not a sensible choice to "repack" the Splunk provided install with custom code, unless you have a specific use case where alternatives are not available.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...