Installation

How to remove/uninstall an app

Roy_9
Motivator

Hello,

We have few apps that are no longer needed in our on premise environment. We maintain git repo for configs.

Can anyone please help me with the steps to uninstall/remove the app.

 

 

Thanks

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The procedure varies depending on the environment.

In a standalone server or independent search heads, indexers, and heavy forwarders, just remove the app directory from $SPLUNK_HOME/etc/apps and restart Splunk.

In a search head cluster, remove the app from $SPLUNK_HOME/etc/shcluster on the SHC Deployer and push the shbundle.

In an indexer cluster, remove the app from $SPLUNK_HOME/etc/manager-apps (or master-apps) and push the bundle.

For universal forwarders, remove the app from the appropriate server class(es).  If no clients use the app, it can be removed from $SPLUNK_HOME/etc/deployment-apps.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The procedure varies depending on the environment.

In a standalone server or independent search heads, indexers, and heavy forwarders, just remove the app directory from $SPLUNK_HOME/etc/apps and restart Splunk.

In a search head cluster, remove the app from $SPLUNK_HOME/etc/shcluster on the SHC Deployer and push the shbundle.

In an indexer cluster, remove the app from $SPLUNK_HOME/etc/manager-apps (or master-apps) and push the bundle.

For universal forwarders, remove the app from the appropriate server class(es).  If no clients use the app, it can be removed from $SPLUNK_HOME/etc/deployment-apps.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...