Splunk® Enterprise

Admin Manual

Download manual as PDF

Download topic as PDF

Apps and add-ons

Apps and add-ons allow you to extend the functionality of the Splunk platform. There are no definitive criteria that universally distinguish an app from an add-on. Both are packaged sets of configuration that you install on your instance of the Splunk platform, and both make it easier to integrate with, or ingest data from, other technologies or vendors.

  • Apps generally offer extensive user interfaces that enable you to work with your data, and they often make use of one or more add-ons to ingest different types of data.
  • Add-ons generally enable the Splunk platform or a Splunk app to ingest or map a particular type of data.

To an admin user, the difference matters very little as both apps and add-ons function as tools to help you get data into the Splunk platform and efficiently use it.

To an app developer, the difference matters more. See dev.splunk.com for guidance on developing apps.

App

An app is an application that runs on the Splunk platform. By default, the Splunk platform includes one basic app that enables you to work with your data: the Search and Reporting app. To address additional use cases, you can install other apps on your instance of Splunk Enterprise. Some apps are free and others are paid. Examples include Splunk App for Microsoft Exchange, Splunk Enterprise Security, and Splunk DB Connect. An app might make use of one or more add-ons to facilitate how it collects or maps particular types of data.

Add-on

An add-on runs on the Splunk platform to provide specific capabilities to apps, such as getting data in, mapping data, or providing saved searches and macros. Examples include Splunk Add-on for Checkpoint OPSEC LEA, Splunk Add-on for Box, and Splunk Add-on for McAfee.


App and add-on support and certification

Anyone can develop an app or add-on for Splunk software. Splunk and members of our community create apps and add-ons and share them with other users of Splunk software via Splunkbase, the online app marketplace. Splunk does not support all apps and add-ons on Splunkbase. Labels in Splunkbase indicate who supports each app or add-on.

  • The Splunk Support team accepts cases and responds to issues only for the apps and add-ons which display a Splunk Supported label on Splunkbase.
    Splunk supported.png
  • Some developers support their own apps and add-ons. These apps and add-ons display a Developer Supported label on Splunkbase.
    Developer supported.png
  • The Splunk developer community supports apps and add-ons which display a Community Supported label on Splunkbase.
    Community supported.png

Further, app developers can obtain Splunk Certification for their app or add-on. This means that Splunk has examined an app or add-on and found that it conforms to best practices for Splunk development. Certification does not, however, mean that Splunk supports an app or add-on. For example, an add-on created by a community developer that is published on Splunkbase and certified by Splunk is not supported by Splunk. Look for a Splunk Supported label on Splunkbase to determine that Splunk supports an app or add-on.

PREVIOUS
KV store troubleshooting tools
  NEXT
Search and Reporting app

This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 7.0.0, 7.0.1


Comments

Adeniel8, an add-on is a technology add-on. <br /><br />In the past, Splunk referred to add-ons as Technology add-ons, or TAs. We’ve dropped the “Technology” from the term, and now refer to them simply as Add-ons. On Splunk Apps, you can still find add-ons that use the older terminology.<br /><br />The Splunk Enterprise Admin manual provides overview information and general guidance for administering add-ons. See Supported Add-ons (http://docs.splunk.com/Documentation/AddOns) for the documentation available for add-ons officially supported by Splunk. Consult the documentation that is provided with other add-ons that are available from Splunk Apps.

Vgenovese
October 20, 2014

Hi,<br /><br />Is there any particular reason why Technology add-ons are not mentioned on this page?

Adaniel8
October 20, 2014

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters