Splunk Enterprise Security

How does one remove the Enterprise Security Suite?

proletariat99
Communicator

I tried $SPLUNK_HOME$/bin/splunk remove app SplunkEnterpriseSecuritySuite and it tells me "app doesn't exist" -- It does... I'm looking at it. Same thing when I try to uninstall any of the SA or DA apps using the splunk binary.

I'm about to hard rip the directories but I just wanted to check to see if anyone had a more elegant way of doing this.

0 Karma
1 Solution

aelliott
Motivator

Deleting the apps in the app directories is the way I did it, it worked like a charm and was though it never existed.

View solution in original post

aelliott
Motivator

Deleting the apps in the app directories is the way I did it, it worked like a charm and was though it never existed.

saurabh_tek
Communicator

But after that i have seen that some apps like Deep security and Fortinet stopped collecting the data in real time..

0 Karma

mloven_splunk
Splunk Employee
Splunk Employee

Hey proletariat99, the change from https to http is expected. The Splunk App for Enterprise Security changes splunkweb from http to https, so upon removal, it would revert back.

Also, if you're antsy about removing apps in the future, you can just move an app to the disabled-apps directory $SPLUNK_HOME/etc/disabled-apps) and restart. That way they're always there if you want to move them back.

wrangler2x
Motivator

Did not noticed disabled-apps before. Interesting.

0 Karma

proletariat99
Communicator

Thanks. I just needed one confirmation before I felt okay pulling the trigger.

So I removed all the apps by using the following commands:
$ rm -rf SplunkEnterpriseSecurity*
$ rm -rf SA-*
$ rm -rf DA-ESS*

The only thing to note is that my local splunk (6.0) instance went from using ssl (https://127.0.0.1:8000) to not ssl (http://127.0.0.1:8000).

I thought that was odd, because I didn't change anything else.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...