Getting Data In

Why is Splunk marking a custom TA as deprecated

DMohn
Motivator

Hi Splunkers

We have built a custom technical add-on for our BlueCoat Appliances. Now Splunk is marking this TA as deprecated (Message: "Deprecated app TA-bluecoat is installed in the enabled state. Please uninstall this app using methods appropriate for your installation")

How can it be that Splunk marks a custom add-on as deprecated?

The app.conf setting check_for_updates is set to false - so there should be no check here.

Can we solve this somehow, as the message is quite nagging, and we are needing the TA?

Thanks for your advice.

0 Karma
1 Solution

DMohn
Motivator

I can give the answer myself here - after some thorough investigation...

The reason was our installation of the Splunk Enterprise Security Suite. During installation the TA was marked as deprecated, as it should have been replaced by a new one.

We have removed the app out of the ESS list of deprecated apps, and everything works fine!

View solution in original post

kmanson
Path Finder

During installation the TA was marked as deprecated, as it should have been replaced by a new one. In my case I am specifically using an app that has the same name as a depreciated app.

To turn off the nagging alert I removed the app from this file.
/opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/install/deprecated_apps.txt

DMohn
Motivator

I can give the answer myself here - after some thorough investigation...

The reason was our installation of the Splunk Enterprise Security Suite. During installation the TA was marked as deprecated, as it should have been replaced by a new one.

We have removed the app out of the ESS list of deprecated apps, and everything works fine!

andrew_bostic1
New Member

I guess a better question is how do you fix this? what needs to be updated to stop this error message?

0 Karma

andrew_bostic1
New Member

Where do you find the ESS list of deprecated apps?

0 Karma

DMohn
Motivator

I found this in the ESS installation log under $SPLUNK_HOME$/var/log/splunk

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

Not sure why the message, but perhaps you can use this TA instead: https://splunkbase.splunk.com/app/2758/

0 Karma

jkat54
SplunkTrust
SplunkTrust

I would assume it's been deprecated as per the Advanced XML deprecation (release 6.3+). Unfortunately I can only comment as I dont know how to disable the message as you desire.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...