Application Management

Refer to the following sections for queries related to application management.

Remove the Application

Follow these steps to remove the application.

  1. Stop Qualys App for Splunk Enterprise:

    $SPLUNK_HOME/bin/splunk stop

  2.  Remove Qualys App for Splunk Enterprise:

    $SPLUNK_HOME/bin/splunk remove app TA-Qualys-Cloud-Connector -auth username:password

To remove the TA app from Splunk Cloud, raise a ticket with Splunk Support.

Know Important File Paths in Splunk

The following table includes the important file paths in Splunk:

File

Path

Index

$SPLUNK_HOME/etc/apps/TA-Qualys-Cloud-Connector/local/inputs.conf

API Credential

$SPLUNK_HOME/ etc/apps/TA-Qualys-Cloud-Connector/local/passwords.conf

Qualys TA Configuration

$SPLUNK_HOME/etc/apps/TA-QualysCloudPlatform/local/ ta-qualys-cloud-connector_account.conf 

$SPLUNK_HOME/etc/apps/TA-QualysCloudPlatform/local/ta-qualys-cloud-connector_settings.conf

Qualys TA log

$SPLUNK_HOME/var/log/splunk/Ta-Qualys-Cloud-Connector/<input_name>/<unique_data_input_name>.log*

Check point

Splunk KV Store collection: TA-Qualys-Cloud-Connector_checkpointer

For details, see Where is the Checkpoint Stored? in the FAQs.