app

noun

A self-service out-of-the box extension that has its own UI context and which can be selected from the App list that appears at the upper right-hand corner of the Splunk UI.

Apps can serve as workspaces for specific kinds of activities and provide Splunk-powered environments tailored to fit the specific needs of organizational workteams such as Unix or Windows system administrators, network security specialists, and website managers, and business analysts.

Apps can include discrete sets of knowledge objects, including saved reports, event types, and custom-designed views and dashboards. Apps can also make use of separately packaged add-ons. A single Splunk installation can run multiple apps simultaneously.

For more information

In the Admin Manual:

In the Developer Manual:

On the Splunk web site:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time