Splunk Search

Disable app on UF using deployment server

AzmathShaik
Path Finder

Hello All,
i have a default app which gets installed on the UF during the installation (part of our install script). to disable this app, i create the app on deployment server with same name and changed the value of state from enabled to disabled.  when i checked uf it is still remaining as enabled. am wondering why it is doing that? can’t i disable the app on UF but install the app

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AzmathShaik,

are you speaking of a default app or another?

if you're speaking of a default app (one installed by Splunk at setup), you cannot disable it.

If you'e speaking of a custom or a Splunkbase app, instead disabling, you can avoid to deploy this app to that UF.

Ciao.

Giuseppe

0 Karma

AzmathShaik
Path Finder

@gcusello , it's a custom app developed by us.  As this app is not pushed to uf using deployment server, we are unable to use deployment server. 

 

we have an custom app which gets downloaded during the installation (part of image) and we are trying to disable it using deployment server. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could install it with installation of UF. Also I propose to use separate app to manage connection to DS (then it’s easy to update with DS, if needed). After initial connection you could deploy same (or different versions) of those from DS. Then you could what ever you want to those (even remove / disable). This is the way how we are managing those. 
r. Ismo

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @AzmathShaik,

you can delete it using the DS, but you have to manage all apps with DS, not only that app.

The only way is a script that deletes the app and restarts Splunk on UF.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...