splunk / splunk-ansible

Ansible playbooks for configuring and managing Splunk Enterprise and Universal Forwarder deployments
357 stars 186 forks source link

add audit_trail to default apps #859

Closed jmeixensperger closed 1 month ago

jmeixensperger commented 1 month ago

This addresses a new behavior in Splunk 9.4.0 where the audit_trail app is shipped with Splunk by default. Updating the default apps here allows us to skip disabling the app on the deployer (shc) and cluster_master (idxc) roles.

In our prelim testing of 9.4.0 with SHC enabled, we observed that audit_trail cannot be disabled on the deployer and throws a cgroup error in the ansible.log.