Apps and add-ons
Apps and add-ons allow you to extend the functionality of the Splunk platform.
App
An app is an application that runs on the Splunk platform. Apps are designed to analyze and display knowledge around a specific data source or data set.
An app might include any or all of the following configurations:
- Dashboards and supporting searches that integrate knowledge of the data source and structure.
- Authentication management and other data source management interfaces.
- An app might require the use of one or more add-ons to facilitate the collection or configuration of data.
Some apps are free and a few are paid. Examples of free apps include: Splunk App for Microsoft Exchange, Splunk App for AWS, and Splunk DB Connect.
Store your apps on a fast, local disk, not on network file system (NFS). Loading apps on NFS can become a performance bottleneck.
Add-on
An add-on provide specific capabilities to assist in gathering, normalizing, and enriching data sources.
An add-on might include any or all of the following configurations:
- Data source input configurations.
- Data parsing and transformation configurations to structure the data for Splunk Enterprise.
- Lookup files for data enrichment.
- Supporting knowledge objects.
Examples include: Splunk Add-on for Checkpoint OPSEC LEA, Splunk Add-on for Box, and Splunk Add-on for McAfee.
App and add-on support
Anyone can develop an app or add-on for Splunk software. Splunk and members of our community create apps and add-ons and share them with other users of Splunk software on the online app marketplace Splunkbase. Splunk does not support all apps and add-ons on Splunkbase.
- For a list of the support options for apps and add-ons, see Support types for apps on Splunkbase on the Splunk Developer Portal.
- For guidance on developing apps, see Developer Guide for Splunk Cloud Platform and Splunk Enterprise on the Splunk Developer Portal.
- For guidance on developing SPL2-based apps, see Create SPL2-based apps on the Splunk Developer Portal.
KV store troubleshooting tools | Search and Reporting app |
This documentation applies to the following versions of Splunk® Enterprise: 9.3.0, 9.3.1, 9.3.2, 9.4.0
Feedback submitted, thanks!