Deployment Architecture

What are the unnecessary apps that ship by default with standard Splunk installation?

the_wolverine
Champion

I want to clean up my distribution for deployment and would like to know which apps are unnecessary for my deployment of Splunk Server (Search heads and Indexers):

Necessary:
search
learned
launcher

Unnecessary (?):
gettingstarted
sample_app
SplunkForwarder
SplunkLightForwarder
legacy

Tags (2)
0 Karma

miteshvohra
Contributor

Splunk binary can be used to convert the instance into to Splunk Light Forwarder or Splunk Heavy Forwarder. Both these roles are different than Splunk Universal Forwarder. After installation of the instance, enabling any of the LF or SplkFwdr app, turns off the WebUI and converts the instance in to the role defined within these Apps.

On the other hand, "sample_app" is used to create custom apps. While creating a custom app, Splunk UI Wizard prompts to select "barebones" or "sample_app" to choose from.

Will dig more for 'legacy' app and update the post again.

- Mitesh Vohra.

0 Karma

yannK
Splunk Employee
Splunk Employee

It's about that.

I would be careful with the forwarder app, because it's is still possible to try to enable them from the manager on "forwarding", and it will fail.

0 Karma

the_wolverine
Champion

This is not yet an official answer as far as I'm aware.

0 Karma

piebob
Splunk Employee
Splunk Employee

please remember to accept the answer when it answers your question.

0 Karma

the_wolverine
Champion

Figured its ok to remove since they are both are disabled by default.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...