I see different forwarders count using the following different ways: Looking at the forwarder management at the license master Looking at the Forwarders:Deployment at the license master Looking at dmc_forwarder_assets.csv inside /opt/splunk/etc/apps/splunk_monitoring_console/lookups/ at the license master So, which one should I guarantee and is there any better way?
... View more
Hello, @isoutamo. Your assumption is correct and I've tried multiple times your solution that also @gcusello mentioned this solution before but that was useless. I think that I'll wait for the interference of threatq support.
... View more
Hi, @gcusello . Sorry for my misunderstanding. The search head is managed by the deployer but the app was installed on the search head only and we just upgraded the splunk version.
... View more
Hello @gcusello Sorry for my late response Unfortunately, it is installed only on the search head that is member. It is in the path /opt/splunk/etc/apps inside it and when I did your solution of stopping this search head , removing the folders and restarting this search head, it is still inside the search head apps with its folder inside the cli and this app has no existence on the deployer
... View more
Hi @gcusello , the app was installed on a single search head neither the deployer nor the search head master. When I apply your solutions, the files keep appearing after restarting the search head and also I don't have the option to disable either the app or the add on from the search head GUI. Thank you for understanding my odd situation.
... View more
Hi, @PickleRick. The threatq app was only installed on a single search head neither the deployer nor the search heads captain. I tried removing everything related to threatq multiple times from this search head but these file keep appearing again and also there is no disable option when I try to disable the threatq app or anything related to it from the search head gui
... View more
Hi, @gcusello . Sorry for my late reply. I already tried your solution but still have the same issue. Also mentioning that the threatq app was installed on a single search head not the deployer or the search head captain
... View more
@gcusello I also did that but every time I do that the app still exists in the gui with its configurations and also the files keep appearing
... View more
I tried to remove the threatq application files from /etc/apps inside the search head but every time I remove them, they keep appearing again even I removed its files from /etc/users. Is there any solution for it?
... View more