# Splunk Appdynamics Controller Admin Setup

> Use when the user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment variable filtering, or privacy validation. Render and validate Splunk AppDynamics Controller administration workflows, including SaaS and on-prem account checks, API clients, OAuth token-file flow, users, groups, roles, SAML, LDAP, account permissions, licensing, license rules, sensitive data collection controls, privacy settings, audit readiness, and data collection dashboards.

- Skill: `chambear2809/splunk-appdynamics-controller-admin-setup` (Agent Skill, multi-file: 9 files)
- Install (CLI): `npx skillmds@latest add chambear2809/splunk-appdynamics-controller-admin-setup`
- Raw SKILL.md: https://api.skillmd.com/api/skills/chambear2809/splunk-appdynamics-controller-admin-setup/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Data & Analytics
- Author: chambear2809 (https://skillmd.com/u/chambear2809)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/chambear2809/splunk-appdynamics-controller-admin-setup

---


# Splunk AppDynamics Controller Admin Setup

## Prerequisites

| Tool or access | Purpose | Verify |
|---|---|---|
| Bash and Python 3 | Run bundled setup and validation helpers | `bash --version && python3 --version` |
| Required product/platform access | Inspect or configure the selected target | Complete the documented preflight |
| Credential files for live modes | Keep secrets out of chat | Verify paths only |

## Workflow Overview

```text
┌───────────┐   ┌───────────────┐   ┌───────────────┐   ┌─────────────────┐
│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │
└───────────┘   └───────────────┘   └───────────────┘   └─────────────────┘
```

## When to Activate

- The user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role
  management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment
  variable.
- Preview and review the splunk appdynamics controller admin setup workflow before any live apply phase.
- Diagnose failed prerequisites, generated assets, configuration, or validation evidence.

## Scope

Follow the documented read-only or render-first path whenever it is available.
This skill does not imply permission to mutate live systems. Require explicit
apply flags, protected credentials, and operator review for state changes.

## Examples

Inspect the supported setup modes before selecting one:

```bash
bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --help
```

Expected output: usage, supported modes, and required arguments are displayed
without changing the target environment.

Inspect validation modes before running completion checks:

```bash
bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh --help
```

Expected output: offline, live, and completion options are displayed when the
skill supports them; help exits without mutation.

## Troubleshooting

| Issue | Cause | Resolution |
|---|---|---|
| Preflight fails | A required tool or access path is missing | Resolve it before rendering or applying |
| Rendered assets are incomplete | Required non-secret inputs are absent | Complete intake and render again |
| Apply is blocked | Review, credentials, or explicit acceptance is missing | Use the documented handoff |
| Validation is incomplete | Live evidence is unavailable | Record the gap and keep completion open |

Controller administration renders documented API/UI runbooks and read-only
probes. This wrapper does not mutate users, groups, roles, API clients, license
rules, identity providers, or privacy controls; `--apply` fails closed. The
license-usage reporter is the concrete read-only action path.

```bash
bash skills/splunk-appdynamics-controller-admin-setup/scripts/setup.sh --render
bash skills/splunk-appdynamics-controller-admin-setup/scripts/validate.sh
bash skills/splunk-appdynamics-controller-admin-setup/scripts/license_usage_report.sh \
  --controller-url "$APPD_CONTROLLER_URL" \
  --account-name "$APPD_ACCOUNT_NAME" \
  --account-id "$APPD_ACCOUNT_ID" \
  --api-client-name "$APPD_API_CLIENT_NAME" \
  --client-secret-file "$APPD_OAUTH_CLIENT_SECRET_FILE" \
  --deep \
  --output-dir ./appd-license-report
```

Secrets such as OAuth client secrets and passwords must be referenced by
chmod-600 files.

The license usage reporter is read-only. It polls documented Controller License
API endpoints and writes a customer-facing Markdown consumption report plus
complete JSON and CSV exports for timestamp-level analysis.

Live validation notes:

- `APPD_ACCOUNT_ID` is the numeric License API account ID, not the account name,
  tenant key, or GUID-like `acctId`/`tntId` claim in an OAuth token.
- `APPD_OAUTH_CLIENT_SECRET_FILE` and `APPD_OAUTH_TOKEN_FILE` must be paths to
  chmod-600 local files, not inline secret values.
- API Client role assignments are separate from user role assignments. If
  license endpoints return 403 for `ACCOUNT_LICENSE`, `LICENSE_USAGE`, or
  `LICENSE_RULE`, assign and save a role on Administration > API Clients.
- OAuth JWT role or account-permission claim counts are diagnostic only; some
  SaaS tokens omit effective API Client permissions even when License API
  readbacks succeed.
- AppDynamics SaaS controllers can require the vendor JSON `Accept` media type;
  the reporter sends that header for OAuth and License API requests.
- Deep mode falls back to application inventory when grouped application usage
  returns an empty `items` object, and host usage degrades cleanly when no host
  IDs are available.

