Splunk Search

How to disable Splunk app using deployment server?

tbavarva
Path Finder

Hi all,

I have deployed an app using a deployment server in Splunk.

Suppose I got a new update for that app and I need to upgrade it.

I have below search:

  1. Since I am using deployment server to push the update on deployment clients, how can I take back up of that app installed on a specific client (I assume it would help me in recover an old app if anything goes wrong)? Will below command help me for this point?
    /opt/splunk/bin/splunk disable app -auth Username:Password

  2. "disabled-apps" folder will help me to revert the changes in any case?

Thanks in advance.

Regards,
Tejas

0 Karma
1 Solution

FrankVl
Ultra Champion

Before starting the update, the app on the client is the same as the app on the deployment server, right?

So just take a backup of the app on the deployment server before you replace the app with the new version. And then the clients will pull the update. In case of any issues, restore backup on deployment server and the clients will pull the old version again.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Before starting the update, the app on the client is the same as the app on the deployment server, right?

So just take a backup of the app on the deployment server before you replace the app with the new version. And then the clients will pull the update. In case of any issues, restore backup on deployment server and the clients will pull the old version again.

0 Karma

tbavarva
Path Finder

Thanks a lot Frank 🙂 and other folks Vijeta and paramagurukarthikeyan for your answers.

0 Karma

tbavarva
Path Finder

Adding more on this:

Can we disable or take back up of any app from deployment server? If yes, how?

Regards,
Tejas

0 Karma

paramagurukarth
Builder

In deployment server, Edit the app.conf and change the state manually.. and restart to push the modified
[install]
state=disabled

0 Karma

Vijeta
Influencer

@tbavarva - You can copy the particular app folder from /opt/splunk/etc/apps/ from your deployment client to take back-up.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...