Splunk Search

How to disable Splunk app using deployment server?

tbavarva
Path Finder

Hi all,

I have deployed an app using a deployment server in Splunk.

Suppose I got a new update for that app and I need to upgrade it.

I have below search:

  1. Since I am using deployment server to push the update on deployment clients, how can I take back up of that app installed on a specific client (I assume it would help me in recover an old app if anything goes wrong)? Will below command help me for this point?
    /opt/splunk/bin/splunk disable app -auth Username:Password

  2. "disabled-apps" folder will help me to revert the changes in any case?

Thanks in advance.

Regards,
Tejas

0 Karma
1 Solution

FrankVl
Ultra Champion

Before starting the update, the app on the client is the same as the app on the deployment server, right?

So just take a backup of the app on the deployment server before you replace the app with the new version. And then the clients will pull the update. In case of any issues, restore backup on deployment server and the clients will pull the old version again.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Before starting the update, the app on the client is the same as the app on the deployment server, right?

So just take a backup of the app on the deployment server before you replace the app with the new version. And then the clients will pull the update. In case of any issues, restore backup on deployment server and the clients will pull the old version again.

0 Karma

tbavarva
Path Finder

Thanks a lot Frank 🙂 and other folks Vijeta and paramagurukarthikeyan for your answers.

0 Karma

tbavarva
Path Finder

Adding more on this:

Can we disable or take back up of any app from deployment server? If yes, how?

Regards,
Tejas

0 Karma

paramagurukarth
Builder

In deployment server, Edit the app.conf and change the state manually.. and restart to push the modified
[install]
state=disabled

0 Karma

Vijeta
Influencer

@tbavarva - You can copy the particular app folder from /opt/splunk/etc/apps/ from your deployment client to take back-up.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...