Apps and add-ons
Apps and add-ons allow you to extend the functionality of the Splunk platform. There are no definitive criteria that universally distinguish an app from an add-on. Both are packaged sets of configuration that you install on your instance of the Splunk platform, and both make it easier to integrate with, or ingest data from, other technologies or vendors.
- Apps generally offer extensive user interfaces that enable you to work with your data, and they often make use of one or more add-ons to ingest different types of data.
- Add-ons generally enable the Splunk platform or a Splunk app to ingest or map a particular type of data.
To an admin user, the difference matters very little as both apps and add-ons function as tools to help you get data into the Splunk platform and efficiently use it.
To an app developer, the difference matters more. See dev.splunk.com for guidance on developing apps.
An app is an application that runs on the Splunk platform. By default, the Splunk platform includes one basic app that enables you to work with your data: the Search and Reporting app. To address additional use cases, you can install other apps on your instance of Splunk Enterprise. Some apps are free and others are paid. Examples include Splunk App for Microsoft Exchange, Splunk Enterprise Security, and Splunk DB Connect. An app might make use of one or more add-ons to facilitate how it collects or maps particular types of data.
An add-on runs on the Splunk platform to provide specific capabilities to apps, such as getting data in, mapping data, or providing saved searches and macros. Examples include Splunk Add-on for Checkpoint OPSEC LEA, Splunk Add-on for Box, and Splunk Add-on for McAfee.
App and add-on support and certification
Anyone can develop an app or add-on for Splunk software. Splunk and members of our community create apps and add-ons and share them with other users of Splunk software via Splunkbase, the online app marketplace. Splunk does not support all apps and add-ons on Splunkbase. Labels in Splunkbase indicate who supports each app or add-on.
- The Splunk Support team accepts cases and responds to issues only for the apps and add-ons which display a Splunk Supported label on Splunkbase.
- Some developers support their own apps and add-ons. These apps and add-ons display a Developer Supported label on Splunkbase.
- The Splunk developer community supports apps and add-ons which display a Community Supported label on Splunkbase.
Further, app developers can obtain Splunk Certification for their app or add-on. This means that Splunk has examined an app or add-on and found that it conforms to best practices for Splunk development. Certification does not, however, mean that Splunk supports an app or add-on. For example, an add-on created by a community developer that is published on Splunkbase and certified by Splunk is not supported by Splunk. Look for a Splunk Supported label on Splunkbase to determine that Splunk supports an app or add-on.
KV store troubleshooting tools
Search and Reporting app
This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 7.0.0, 7.0.1