Splunk® Enterprise

Admin Manual

Download manual as PDF

Download topic as PDF

Apps and add-ons

Users often ask for definitions of app and add-on in an effort to determine what differentiates them from each other. There are no definitive criteria that universally distinguish an app from an add-on. Both are packaged sets of configuration that you install on your instance of Splunk Enterprise, and both make it easier to integrate with, or ingest data from, other technologies or vendors.

  • Apps generally offer extensive user interfaces that enable you to work with your data, and they often make use of one or more add-ons to ingest different types of data.
  • Add-ons generally enable Splunk Enterprise, or a Splunk app, to ingest or map a particular type of data.

To an Admin user, the difference should matter very little as both apps and add-ons function as tools to help you get data into Splunk Enterprise, then efficiently use it.

To an app developer, the difference matters more: see dev.splunk.com for guidance on developing an app.


An app is an application that runs on Splunk Enterprise. Out of the box, Splunk Enterprise includes one basic, default app that enables you to work with your data: the Search and Reporting app. To address use cases beyond the basic, you can install many other apps, some free, some paid, on your instance of Splunk Enterprise. Examples include Splunk App for Microsoft Exchange, Splunk App for Enterprise Security, and Splunk DB Connect. An app may make use of one or more add-ons to facilitate how it collects or maps particular types of data.


An add-on runs on Splunk Enterprise to provide specific capabilities to apps, such as getting data in, mapping data, or providing saved searches and macros. Examples include Splunk Add-on for Checkpoint OPSEC LEA, Splunk Add-on for Box, and Splunk Add-on for McAfee.

App and add-on support and certification

Anyone can develop an app or add-on for Splunk software. Splunk and members of our community create apps and add-ons and share them with other users of Splunk software via Splunkbase, the online app marketplace. Splunk does not support all apps and add-ons on Splunkbase. Labels in Splunkbase indicate who supports each app or add-on.

  • The Splunk Support team accepts cases and responds to issues only for the apps and add-ons which display a Splunk Supported label on Splunkbase.
  • Some developers support their own apps and add-ons. These apps and add-ons display a Developer Supported label on Splunkbase.
  • The Splunk developer community supports apps and add-ons which display a Community Supported label on Splunkbase.

Splunk supported.png Developer supported.png Community supported.png

Further, app developers can obtain Splunk Certification for their app or add-on. This means that Splunk has examined an app or add-on and found that it conforms to best practices for Splunk development. Certification does not, however, mean that Splunk supports an app or add-on. For example, an add-on created by a community developer that is published on Splunkbase and certified by Splunk is not supported by Splunk. Look for a Splunk Supported label on Splunkbase to determine that Splunk supports an app or add-on.

KV store troubleshooting tools
Search and Reporting app

This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0


Adeniel8, an add-on is a technology add-on. <br /><br />In the past, Splunk referred to add-ons as Technology add-ons, or TAs. We’ve dropped the “Technology” from the term, and now refer to them simply as Add-ons. On Splunk Apps, you can still find add-ons that use the older terminology.<br /><br />The Splunk Enterprise Admin manual provides overview information and general guidance for administering add-ons. See Supported Add-ons (http://docs.splunk.com/Documentation/AddOns) for the documentation available for add-ons officially supported by Splunk. Consult the documentation that is provided with other add-ons that are available from Splunk Apps.

October 20, 2014

Hi,<br /><br />Is there any particular reason why Technology add-ons are not mentioned on this page?

October 20, 2014

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters