Splunk® Enterprise

Developing Views and Apps for Splunk Web

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Step 4: Add objects

Objects are configurations within your app that are local in scope and permissionable. This means that objects can be scoped to an app and can have read and write permissions set. For example, saved searches are objects that only show up within a given app (unless configured to be global). Users can be granted read only or read/write permissions on any saved search.

When you build an app, you typically add a number of objects that add knowledge to your app, making it more useful. The Knowledge Manager manual covers the objects available and their configuration details.

Available object types

Here's a list of object types that are available:

  • Saved searches
  • Event types
  • Dashboards, form searches, and other views
  • Fields
  • Tags
  • Field extractions
  • Lookups
  • Search commands

Each of these object types has a use within your app. Use this page as a reference to figure out which objects you want to use, then refer to the topic in the Knowledge Manager manual to learn more about how to configure the object you want.

Saved searches and reports

Saved searches and reports are the building block of most apps. Use saved searches and reports to dynamically capture important pieces of your data. Display them in your app on a dashboard, or add them to a drop-down menu in Splunk Web to run as needed. Use saved searches as a shortcut to launch interesting and relevant searches into whatever data you've loaded into your app. Saved searches are useful when building dashboards as you can schedule your saved search to run and collect data so that when your dashboard loads, the search results are already available.

Event types

Configure event types to capture and share knowledge in your app. Learn more about event types in the Knowledge Manager manual.

Fields

Splunk Enterprise automatically extracts fields from your data. You may want to add in your own custom fields to your app, however. For example, you may have some custom data in your app that you want to showcase in your results by creating a new field. Read more about fields in the Knowledge Manager manual.

Tags

Tags are another way to add metadata to your data. Any tags you create you can add to your app. Read more about tags in the Knowledge Manager manual.

Views

Customize Splunk Web by building views. Views include dashboards and search views and present the knowledge objects you've built in your app. Dashboards generally contain links to relevant searches, as well as any reports you want to display upon loading your app. Search views let you run searches on an ad hoc basis.

Permissions for objects

Set default permissions for objects in your app in Step 5: set permissions.

PREVIOUS
Step 3: Add configurations
  NEXT
Step 5: Set permissions

This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters