Splunk® Enterprise

Developing Views and Apps for Splunk Web

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Step 4: Add objects

Objects are configurations within your app that are local in scope and permissionable. This means that objects can be scoped to an app and can have read and write permissions set. For example, saved searches are objects that only show up within a given app (unless configured to be global). Users can be granted read only or read/write permissions on any saved search.

When you build an app, you typically add a number of objects that add knowledge to your app, making it more useful. The Knowledge Manager manual covers the objects available and their configuration details.

Available object types

Here's a list of object types that are available:

  • Saved searches
  • Event types
  • Dashboards, form searches, and other views
  • Fields
  • Tags
  • Field extractions
  • Lookups
  • Search commands

Each of these object types has a use within your app. Use this page as a reference to figure out which objects you want to use, then refer to the topic in the Knowledge Manager manual to learn more about how to configure the object you want.

Saved searches and reports

Saved searches and reports are the building block of most apps. Use saved searches and reports to dynamically capture important pieces of your data. Display them in your app on a dashboard, or add them to a drop-down menu in Splunk Web to run as needed. Use saved searches as a shortcut to launch interesting and relevant searches into whatever data you've loaded into your app. Saved searches are useful when building dashboards as you can schedule your saved search to run and collect data so that when your dashboard loads, the search results are already available.

Event types

Configure event types to capture and share knowledge in your app. Learn more about event types in the Knowledge Manager manual.


Splunk Enterprise automatically extracts fields from your data. You may want to add in your own custom fields to your app, however. For example, you may have some custom data in your app that you want to showcase in your results by creating a new field. Read more about fields in the Knowledge Manager manual.


Tags are another way to add metadata to your data. Any tags you create you can add to your app. Read more about tags in the Knowledge Manager manual.


Customize Splunk Web by building views. Views include dashboards and search views and present the knowledge objects you've built in your app. Dashboards generally contain links to relevant searches, as well as any reports you want to display upon loading your app. Search views let you run searches on an ad hoc basis.

Permissions for objects

Set default permissions for objects in your app in Step 5: set permissions.

Last modified on 18 August, 2016
Step 3: Add configurations
Step 5: Set permissions

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters