Deployment Architecture

What are the unnecessary apps that ship by default with standard Splunk installation?

the_wolverine
Champion

I want to clean up my distribution for deployment and would like to know which apps are unnecessary for my deployment of Splunk Server (Search heads and Indexers):

Necessary:
search
learned
launcher

Unnecessary (?):
gettingstarted
sample_app
SplunkForwarder
SplunkLightForwarder
legacy

Tags (2)
0 Karma

miteshvohra
Contributor

Splunk binary can be used to convert the instance into to Splunk Light Forwarder or Splunk Heavy Forwarder. Both these roles are different than Splunk Universal Forwarder. After installation of the instance, enabling any of the LF or SplkFwdr app, turns off the WebUI and converts the instance in to the role defined within these Apps.

On the other hand, "sample_app" is used to create custom apps. While creating a custom app, Splunk UI Wizard prompts to select "barebones" or "sample_app" to choose from.

Will dig more for 'legacy' app and update the post again.

- Mitesh Vohra.

0 Karma

yannK
Splunk Employee
Splunk Employee

It's about that.

I would be careful with the forwarder app, because it's is still possible to try to enable them from the manager on "forwarding", and it will fail.

0 Karma

the_wolverine
Champion

This is not yet an official answer as far as I'm aware.

0 Karma

piebob
Splunk Employee
Splunk Employee

please remember to accept the answer when it answers your question.

0 Karma

the_wolverine
Champion

Figured its ok to remove since they are both are disabled by default.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...