Deployment Architecture

Is this the correct way to use appOrder in user-prefs.conf on a search head cluster?

lycollicott
Motivator

I want to sort everyone's apps in the Launcher, so on my deployer I created an app called MY_user-prefs. It contains a single file MY_user-prefs\local\user-prefs.conf that looks like this:

[general_default]
appOrder = MY_Docs,search,pingfederate,data_curator,SplunkAppForWebAnalytics

After I apply the shcluster-bundle, the order of apps in the Launcher is unchanged. Any suggestions?

EDIT: I forgot to mention that if I manually go to each search head and add the appOrder parameter to the standard user-prefs app, then it works. I just would like to do it centrally from the deployer whenever I need to make adjustments.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You need to export this app globally. The user-prefs is a per app setting.

Read the prologue in user-prefs.conf.spec here http://docs.splunk.com/Documentation/Splunk/6.1.6/Admin/User-prefsconf

Here's how to export globally:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Defaultmetaconf

/appName/metadata/default.meta:

[]
export=system

View solution in original post

jkat54
SplunkTrust
SplunkTrust

You need to export this app globally. The user-prefs is a per app setting.

Read the prologue in user-prefs.conf.spec here http://docs.splunk.com/Documentation/Splunk/6.1.6/Admin/User-prefsconf

Here's how to export globally:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Defaultmetaconf

/appName/metadata/default.meta:

[]
export=system

harsmarvania57
Ultra Champion

Hi @lycollicott,

After pushing bundle from deployer, can you please check $SPLUNK_HOME/bin/splunk cmd btool user-prefs --debug list on any of the search head, the output will show that appOrder is taking from which app. So you can figure out whether appOrder parameter is taking from correct app or not.

Thanks,
Harshil

0 Karma

lycollicott
Motivator

Yes, I did that. The appOrder is read from the deployed file, but it doesn't seem to have any affect.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...