Splunk Search

Saved Search runs after Uninstallation of App

vr2312
Builder

I installed an App from Splunkbase for Testing purposes.

The app came with Custom Searches which i had scheduled as per the testing phase.

I had uninstalled the app, however, i can still see searches run from the app though the app no longer exists.

it is not creating much of a trouble but i am wondering from where the searches are being run and how i can stop it.

0 Karma
1 Solution

vr2312
Builder

Thanks for the input @ybongart

Sorted the answer by myself.

The issue was occurring due to a Search head which was brought up which happened to be a clone. hence the server.conf/inputs.conf had the disabled searches search head server name.

View solution in original post

0 Karma

vr2312
Builder

Thanks for the input @ybongart

Sorted the answer by myself.

The issue was occurring due to a Search head which was brought up which happened to be a clone. hence the server.conf/inputs.conf had the disabled searches search head server name.

0 Karma

ybongart_splunk
Splunk Employee
Splunk Employee

If you made any changes to saved searches in the app, check your user folder for personal copies of the app, specifically in $SPLUNK_HOME/etc/users/{user}/{app}/local/savedsearches.conf

See https://docs.splunk.com/Documentation/Splunk/latest/Admin/Configurationfiledirectories

Also, you should see the search listed under Settings->Searches, Reports, and Alerts.

There you may be able to see the Owner and if "Sharing" is "Private" then it will be found under $SPLUNK_HOME/etc/users/...

You can also disable it from there by selecting Actions->Edit->Disable.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...