add-on

noun

A reusable Splunk component. Any member of the Splunk community can build an add-on and share it with other Splunk users. Add-ons include custom configurations, scripts, data inputs, custom reports or views, and themes that can change the look and feel of Splunk. A single add-on can be used in multiple apps, suites, or solutions. Add-ons are downloaded from the Splunk website or from the Launcher.

For more information

In the Admin Manual:

In the Developing Views and Apps for Splunk Web Manual:

On the Splunk website:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time