Splunk® Enterprise

Module System User Manual

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF


The Module System exposes the core Splunk knowledge base for the purpose of building custom app customized for your application domain. A framework is inherently complex and requires suitable documentation and examples to be able to use it effectively. Here, you'll find documentation that covers the key concepts and reference material needed to begin creating apps.

You'll find this documentation to be applicable to different phases of the development lifecycle and different levels of expertise. For example, Getting Started is most useful for initial familiarization with the framework and development process, while the reference API might be consulted frequently to refresh your memory about programming details. Because examples and learn-by-doing provide the most effective techniques for learning complex topics, an example accompanies most discussion. In particular, the Cookbook includes a complete set of examples, in the menu above, that you can actually run in the context of this app.

Become familiar with terminology. If you are new to Module System development, read Getting Started. Consult the Cookbook and its associated examples to learn how to implement common use cases. You'll find the implementation details in the Reference useful after you've learned the basics of how to develop in the Module System environment.

The documentation set provides the various system views a developer needs to understand and use the Module System.


This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters