Deployment Architecture

Is it possible to enable or disable an application state in app.conf via deployment server?

Priya312
Explorer

Hi,
I'm trying to disable a forwarder. For that, i'm changing the state to disabled in app.conf of collector class.
I'm performing this activity via deployment server.

But whenever i modify app.conf via deployment server, in the forwarder, the state is not getting changed to disable.
If i manually change the app.conf in the forwarder, the state is getting changed to disable.

Please help me to know whether via deployment server, we can't enable/disable an app in Splunk.

1 Solution

Ayn
Legend

You set this in serverclass.conf.

stateOnClient = enabled | disabled | noop
    * If set to "enabled", sets the application state to enabled on the client, regardless of state on the deployment server.
    * If set to "disabled", set the application state to disabled on the client, regardless of state on the deployment server.
    * If set to "noop", the state on the client will be the same as on the deployment server.
    * Can be overridden at the serverClass level and the serverClass:app level.
    * Defaults to enabled.

View solution in original post

splunkreal
Motivator

I have to delete app.conf sometimes in deployment-apps then reload deploy-server to reset the state.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

Ayn
Legend

You set this in serverclass.conf.

stateOnClient = enabled | disabled | noop
    * If set to "enabled", sets the application state to enabled on the client, regardless of state on the deployment server.
    * If set to "disabled", set the application state to disabled on the client, regardless of state on the deployment server.
    * If set to "noop", the state on the client will be the same as on the deployment server.
    * Can be overridden at the serverClass level and the serverClass:app level.
    * Defaults to enabled.
Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...