Deployment Architecture

Is it possible to enable or disable an application state in app.conf via deployment server?

Priya312
Explorer

Hi,
I'm trying to disable a forwarder. For that, i'm changing the state to disabled in app.conf of collector class.
I'm performing this activity via deployment server.

But whenever i modify app.conf via deployment server, in the forwarder, the state is not getting changed to disable.
If i manually change the app.conf in the forwarder, the state is getting changed to disable.

Please help me to know whether via deployment server, we can't enable/disable an app in Splunk.

1 Solution

Ayn
Legend

You set this in serverclass.conf.

stateOnClient = enabled | disabled | noop
    * If set to "enabled", sets the application state to enabled on the client, regardless of state on the deployment server.
    * If set to "disabled", set the application state to disabled on the client, regardless of state on the deployment server.
    * If set to "noop", the state on the client will be the same as on the deployment server.
    * Can be overridden at the serverClass level and the serverClass:app level.
    * Defaults to enabled.

View solution in original post

splunkreal
Motivator

I have to delete app.conf sometimes in deployment-apps then reload deploy-server to reset the state.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

Ayn
Legend

You set this in serverclass.conf.

stateOnClient = enabled | disabled | noop
    * If set to "enabled", sets the application state to enabled on the client, regardless of state on the deployment server.
    * If set to "disabled", set the application state to disabled on the client, regardless of state on the deployment server.
    * If set to "noop", the state on the client will be the same as on the deployment server.
    * Can be overridden at the serverClass level and the serverClass:app level.
    * Defaults to enabled.
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...