Security

web.conf - updateCheckerBaseURL

pduvofmr
Path Finder

Hi @ All,

i create a little app to set "updateCheckerBaseURL" value to "0".
Then i copied it to "/opt/splunk/etc/deployment-apps" on Deployment Server and changed folder permissions to the splunk user.

The app where deployed to the clients and "./splunk cmd btool web list settings" displays "updateCheckerBaseURL = 0", but the update notification where still there.

If i set "updateCheckerBaseURL = 0" direct to "$SPLUNK_HOME/etc/system/local/web.conf", then the update notification where disabled.

Please advise - Markus

0 Karma
1 Solution

manjunathmeti
Champion

I am using below attributes under [settings] stanza in web.conf in an app and it works fine.

[settings]    
# Disable Splunk automatic checking for new app versions
updateCheckerBaseURL = 0

You may need to provide read permissions to the app in metadata. Create a metadata directory in your app and create default.meta in it with below content.

[]
access = read : [ * ], write : [ admin ]
export = system

View solution in original post

manjunathmeti
Champion

I am using below attributes under [settings] stanza in web.conf in an app and it works fine.

[settings]    
# Disable Splunk automatic checking for new app versions
updateCheckerBaseURL = 0

You may need to provide read permissions to the app in metadata. Create a metadata directory in your app and create default.meta in it with below content.

[]
access = read : [ * ], write : [ admin ]
export = system
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...