Deployment Architecture

Is it possible to enable or disable an application state in app.conf via deployment server?

Priya312
Explorer

Hi,
I'm trying to disable a forwarder. For that, i'm changing the state to disabled in app.conf of collector class.
I'm performing this activity via deployment server.

But whenever i modify app.conf via deployment server, in the forwarder, the state is not getting changed to disable.
If i manually change the app.conf in the forwarder, the state is getting changed to disable.

Please help me to know whether via deployment server, we can't enable/disable an app in Splunk.

1 Solution

Ayn
Legend

You set this in serverclass.conf.

stateOnClient = enabled | disabled | noop
    * If set to "enabled", sets the application state to enabled on the client, regardless of state on the deployment server.
    * If set to "disabled", set the application state to disabled on the client, regardless of state on the deployment server.
    * If set to "noop", the state on the client will be the same as on the deployment server.
    * Can be overridden at the serverClass level and the serverClass:app level.
    * Defaults to enabled.

View solution in original post

splunkreal
Motivator

I have to delete app.conf sometimes in deployment-apps then reload deploy-server to reset the state.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

Ayn
Legend

You set this in serverclass.conf.

stateOnClient = enabled | disabled | noop
    * If set to "enabled", sets the application state to enabled on the client, regardless of state on the deployment server.
    * If set to "disabled", set the application state to disabled on the client, regardless of state on the deployment server.
    * If set to "noop", the state on the client will be the same as on the deployment server.
    * Can be overridden at the serverClass level and the serverClass:app level.
    * Defaults to enabled.
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...