Splunk AppDynamics Controller Admin Setup
Prerequisites
| Tool or access |
Purpose |
Verify |
| Bash and Python 3 |
Run bundled setup and validation helpers |
bash --version && python3 --version |
| Required product/platform access |
Inspect or configure the selected target |
Complete the documented preflight |
| Credential files for live modes |
Keep secrets out of chat |
Verify paths only |
Workflow Overview
┌───────────┐ ┌───────────────┐ ┌───────────────┐ ┌─────────────────┐
│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │
└───────────┘ └───────────────┘ └───────────────┘ └─────────────────┘
When to Activate
- The user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role
management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment
variable.
- Preview and review the splunk appdynamics controller admin setup workflow before any live apply phase.
- Diagnose failed prerequisites, generated assets, configuration, or validation evidence.
Scope
Follow the documented read-only or render-first path whenever it is available.
This skill does not imply permission to mutate live systems. Require explicit
apply flags, protected credentials, and operator review for state changes.
Examples
Inspect the supported setup modes before selecting one:
bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --help
Expected output: usage, supported modes, and required arguments are displayed
without changing the target environment.
Inspect validation modes before running completion checks:
bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh --help
Expected output: offline, live, and completion options are displayed when the
skill supports them; help exits without mutation.
Troubleshooting
| Issue |
Cause |
Resolution |
| Preflight fails |
A required tool or access path is missing |
Resolve it before rendering or applying |
| Rendered assets are incomplete |
Required non-secret inputs are absent |
Complete intake and render again |
| Apply is blocked |
Review, credentials, or explicit acceptance is missing |
Use the documented handoff |
| Validation is incomplete |
Live evidence is unavailable |
Record the gap and keep completion open |
Controller administration renders documented API/UI runbooks and read-only
probes. This wrapper does not mutate users, groups, roles, API clients, license
rules, identity providers, or privacy controls; --apply fails closed. The
license-usage reporter is the concrete read-only action path.
bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --render
bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh
bash skills/splunk-appdynamics-controller-admin-setup/scripts/license_usage_report.sh \
--controller-url "$APPD_CONTROLLER_URL" \
--account-name "$APPD_ACCOUNT_NAME" \
--account-id "$APPD_ACCOUNT_ID" \
--api-client-name "$APPD_API_CLIENT_NAME" \
--client-secret-file "$APPD_OAUTH_CLIENT_SECRET_FILE" \
--deep \
--output-dir ./appd-license-report
Secrets such as OAuth client secrets and passwords must be referenced by
chmod-600 files.
The license usage reporter is read-only. It polls documented Controller License
API endpoints and writes a customer-facing Markdown consumption report plus
complete JSON and CSV exports for timestamp-level analysis.
Live validation notes:
APPD_ACCOUNT_ID is the numeric License API account ID, not the account name,
tenant key, or GUID-like acctId/tntId claim in an OAuth token.
APPD_OAUTH_CLIENT_SECRET_FILE and APPD_OAUTH_TOKEN_FILE must be paths to
chmod-600 local files, not inline secret values.
- API Client role assignments are separate from user role assignments. If
license endpoints return 403 for
ACCOUNT_LICENSE, LICENSE_USAGE, or
LICENSE_RULE, assign and save a role on Administration > API Clients.
- OAuth JWT role or account-permission claim counts are diagnostic only; some
SaaS tokens omit effective API Client permissions even when License API
readbacks succeed.
- AppDynamics SaaS controllers can require the vendor JSON
Accept media type;
the reporter sends that header for OAuth and License API requests.
- Deep mode falls back to application inventory when grouped application usage
returns an empty
items object, and host usage degrades cleanly when no host
IDs are available.
1---2name: splunk-appdynamics-controller-admin-setup3description: Use when the user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment variable filtering, or privacy validation. Render and validate Splunk AppDynamics Controller administration workflows, including SaaS and on-prem account checks, API clients, OAuth token-file flow, users, groups, roles, SAML, LDAP, account permissions, licensing, license rules, sensitive data collection controls, privacy settings, audit readiness, and data collection dashboards.4---56# Splunk AppDynamics Controller Admin Setup78## Prerequisites910| Tool or access | Purpose | Verify |11|---|---|---|12| Bash and Python 3 | Run bundled setup and validation helpers | `bash --version && python3 --version` |13| Required product/platform access | Inspect or configure the selected target | Complete the documented preflight |14| Credential files for live modes | Keep secrets out of chat | Verify paths only |1516## Workflow Overview1718```text19┌───────────┐ ┌───────────────┐ ┌───────────────┐ ┌─────────────────┐20│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │21└───────────┘ └───────────────┘ └───────────────┘ └─────────────────┘22```2324## When to Activate2526- The user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role27 management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment28 variable.29- Preview and review the splunk appdynamics controller admin setup workflow before any live apply phase.30- Diagnose failed prerequisites, generated assets, configuration, or validation evidence.3132## Scope3334Follow the documented read-only or render-first path whenever it is available.35This skill does not imply permission to mutate live systems. Require explicit36apply flags, protected credentials, and operator review for state changes.3738## Examples3940Inspect the supported setup modes before selecting one:4142```bash43bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --help44```4546Expected output: usage, supported modes, and required arguments are displayed47without changing the target environment.4849Inspect validation modes before running completion checks:5051```bash52bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh --help53```5455Expected output: offline, live, and completion options are displayed when the56skill supports them; help exits without mutation.5758## Troubleshooting5960| Issue | Cause | Resolution |61|---|---|---|62| Preflight fails | A required tool or access path is missing | Resolve it before rendering or applying |63| Rendered assets are incomplete | Required non-secret inputs are absent | Complete intake and render again |64| Apply is blocked | Review, credentials, or explicit acceptance is missing | Use the documented handoff |65| Validation is incomplete | Live evidence is unavailable | Record the gap and keep completion open |6667Controller administration renders documented API/UI runbooks and read-only68probes. This wrapper does not mutate users, groups, roles, API clients, license69rules, identity providers, or privacy controls; `--apply` fails closed. The70license-usage reporter is the concrete read-only action path.7172```bash73bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --render74bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh75bash skills/splunk-appdynamics-controller-admin-setup/scripts/license_usage_report.sh \76 --controller-url "$APPD_CONTROLLER_URL" \77 --account-name "$APPD_ACCOUNT_NAME" \78 --account-id "$APPD_ACCOUNT_ID" \79 --api-client-name "$APPD_API_CLIENT_NAME" \80 --client-secret-file "$APPD_OAUTH_CLIENT_SECRET_FILE" \81 --deep \82 --output-dir ./appd-license-report83```8485Secrets such as OAuth client secrets and passwords must be referenced by86chmod-600 files.8788The license usage reporter is read-only. It polls documented Controller License89API endpoints and writes a customer-facing Markdown consumption report plus90complete JSON and CSV exports for timestamp-level analysis.9192Live validation notes:9394- `APPD_ACCOUNT_ID` is the numeric License API account ID, not the account name,95 tenant key, or GUID-like `acctId`/`tntId` claim in an OAuth token.96- `APPD_OAUTH_CLIENT_SECRET_FILE` and `APPD_OAUTH_TOKEN_FILE` must be paths to97 chmod-600 local files, not inline secret values.98- API Client role assignments are separate from user role assignments. If99 license endpoints return 403 for `ACCOUNT_LICENSE`, `LICENSE_USAGE`, or100 `LICENSE_RULE`, assign and save a role on Administration > API Clients.101- OAuth JWT role or account-permission claim counts are diagnostic only; some102 SaaS tokens omit effective API Client permissions even when License API103 readbacks succeed.104- AppDynamics SaaS controllers can require the vendor JSON `Accept` media type;105 the reporter sends that header for OAuth and License API requests.106- Deep mode falls back to application inventory when grouped application usage107 returns an empty `items` object, and host usage degrades cleanly when no host108 IDs are available.